Information
If auditing is enabled late in the startup process, the actions of some start-up processes may not be audited. Some audit systems also maintain state information only available if auditing is enabled before a given process is created.
Satisfies: SRG-APP-000092-NDM-000224, SRG-APP-000026-NDM-000208, SRG-APP-000027-NDM-000209, SRG-APP-000028-NDM-000210, SRG-APP-000029-NDM-000211, SRG-APP-000091-NDM-000223, SRG-APP-000095-NDM-000225, SRG-APP-000096-NDM-000226, SRG-APP-000097-NDM-000227, SRG-APP-000098-NDM-000228, SRG-APP-000099-NDM-000229, SRG-APP-000100-NDM-000230, SRG-APP-000101-NDM-000231, SRG-APP-000319-NDM-000283, SRG-APP-000343-NDM-000289, SRG-APP-000381-NDM-000305, SRG-APP-000495-NDM-000318, SRG-APP-000499-NDM-000319, SRG-APP-000503-NDM-000320, SRG-APP-000504-NDM-000321, SRG-APP-000505-NDM-000322, SRG-APP-000506-NDM-000323
Solution
Configure the OS10 Switch to initiate session auditing upon startup:
OS10(config)# logging audit enable
Item Details
Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY
References: 800-53|AC-2(4), 800-53|AC-6(9), 800-53|AU-3, 800-53|AU-3(1), 800-53|AU-12c., 800-53|AU-14(1), CAT|II, CCI|CCI-000018, CCI|CCI-000130, CCI|CCI-000131, CCI|CCI-000132, CCI|CCI-000133, CCI|CCI-000134, CCI|CCI-000135, CCI|CCI-000172, CCI|CCI-001403, CCI|CCI-001404, CCI|CCI-001405, CCI|CCI-001464, CCI|CCI-001487, CCI|CCI-002130, CCI|CCI-002234, CCI|CCI-003938, Rule-ID|SV-269774r1051707_rule, STIG-ID|OS10-NDM-000180, Vuln-ID|V-269774
Control ID: f7ffca628b348ab1bf50ff17f90ea6a11617e58233e02a25ee9c835924912090