GEN000440 - Successful and unsuccessful logins and logouts must be logged.

Information

Monitoring and recording successful and unsuccessful logins assist in tracking unauthorized access to the system. Without this logging, the ability to track unauthorized activity to specific user accounts may be diminished.

Solution

Verify that login logs are handled correctly in the /etc/syslog.conf file. Edit the /etc/syslog.conf file and add one of the entries below.

auth.debug /var/log/authlog
OR
auth.* /var/log/authlog

Verify that service startup scripts for syslog and utmp (if present) are enabled.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_SPARC_V2R4_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c., CAT|II, CCI|CCI-000172, Rule-ID|SV-226451r603265_rule, STIG-ID|GEN000440, STIG-Legacy|SV-27080, STIG-Legacy|V-765, Vuln-ID|V-226451

Plugin: Unix

Control ID: 3fa183dd24cbb708f2a8b451bfb1cb7b9258b195b9bb446701b530ec7580cd25