UBTU-20-010198 - The Ubuntu operating system must initiate session audits at system start-up.

Information

If auditing is enabled late in the start-up process, the actions of some start-up processes may not be audited. Some audit systems also maintain state information only available if auditing is enabled before a given process is created.

Solution

Configure the Ubuntu operating system to produce audit records at system startup.

Edit the '/etc/default/grub' file and add 'audit=1' to the 'GRUB_CMDLINE_LINUX' option.

To update the grub config file, run:

$ sudo update-grub

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CAN_Ubuntu_20-04_LTS_V1R10_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-14(1), CAT|II, CCI|CCI-001464, Rule-ID|SV-238299r654072_rule, STIG-ID|UBTU-20-010198, Vuln-ID|V-238299

Plugin: Unix

Control ID: cb69f986094f7de467dc4a9dfaaed5ed1c943792a96c2c8c8767d77a84e181f0