SOL-11.1-010260 - The operating system must automatically audit account disabling actions - getpolicy

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version


Without auditing, malicious activity cannot be detected.


The Audit Configuration profile is required. All audit flags must be enabled in a single command.

This action applies to the global zone only. Determine the zone currently being secured.

# zonename

If the command output is 'global', this action applies.

For Solaris 11, 11.1, 11.2, and 11.3:
# pfexec auditconfig -setflags cusa,-ps,fd,-fa,fm

For Solaris 11.4 or newer:
# pfexec auditconfig -setflags cusa,-fa,-ex,-ps,fd,fm

Enable the audit policy to collect command line arguments.

# pfexec auditconfig -setpolicy +argv

These changes will not affect users that are currently logged in.

See Also

Item Details

References: CAT|II, CCI|CCI-001404, Rule-ID|SV-216261r877426_rule, STIG-ID|SOL-11.1-010260, STIG-Legacy|SV-60687, STIG-Legacy|V-47811, Vuln-ID|V-216261

Plugin: Unix

Control ID: e36992dd6606691306ae3e76a95fe3fde192e7cfa5934d3986cdf83571f762b3