RHEL-06-000145 - The operating system must produce audit records containing sufficient information to establish the identity of any user/subject associated with the event - 'PROCESS_CHECK'.

Information

Ensuring the 'auditd' service is active ensures audit records generated by the kernel can be written to disk, or that appropriate actions will be taken if other obstacles exist.

Solution

The 'auditd' service is an essential userspace component of the Linux Auditing System, as it is responsible for writing audit records to disk. The 'auditd' service can be enabled with the following commands:

# chkconfig auditd on
# service auditd start

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_6_V2R2_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-3, CAT|II, CCI|CCI-001487, Rule-ID|SV-217944r603264_rule, STIG-ID|RHEL-06-000145, STIG-Legacy|SV-50429, STIG-Legacy|V-38628, Vuln-ID|V-217944

Plugin: Unix

Control ID: 0ee57a8dad5485ce609c4d636e62dc96e106a61a934a171a47feb5e2ceed5fb3