800-53|AU-5

Title

RESPONSE TO AUDIT PROCESSING FAILURES

Description

The information system:

Supplemental

Audit processing failures include, for example, software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded. Organizations may choose to define additional actions for different audit processing failures (e.g., by type, by location, by severity, or a combination of such factors). This control applies to each audit data storage repository (i.e., distinct information system component where audit records are stored), the total audit storage capacity of organizations (i.e., all audit data storage repositories combined), or both.

Reference Item Details

Related: AU-4,SI-12

Category: AUDIT AND ACCOUNTABILITY

Family: AUDIT AND ACCOUNTABILITY

Priority: P1

Baseline Impact: LOW,MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.3.2.1 Set 'Audit: Shut down system immediately if unable to log security audits' to 'Disabled'WindowsCIS Windows 8 L1 v1.0.0
1.125 UBTU-22-653040UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT III
1.175 UBTU-24-900960UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT III
1.282 OL08-00-030730UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.283 OL08-00-030731UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.372 RHEL-09-653035UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.373 RHEL-09-653040UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.374 RHEL-09-653045UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.375 RHEL-09-653050UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.379 RHEL-09-653070UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
2.3.2.2 Ensure 'Audit: Shut down system immediately if unable to log security audits' is set to 'Disabled'WindowsCIS Windows 7 Workstation Level 1 v3.2.0
2.3.2.2 Ensure 'Audit: Shut down system immediately if unable to log security audits' is set to 'Disabled'WindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0
3.092 - The system must generate an audit event when the audit log reaches a percentage of full threshold.WindowsDISA Windows Vista STIG v6r41
4.1.1.2 Ensure system is disabled when audit logs are full - 'action_mail_acct is configured'UnixCIS Amazon Linux v2.1.0 L2
4.1.1.2 Ensure system is disabled when audit logs are full - 'action_mail_acct'UnixCIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0
4.1.1.2 Ensure system is disabled when audit logs are full - 'action_mail_acct'UnixCIS Ubuntu Linux 14.04 LTS Workstation L2 v2.1.0
4.1.1.2 Ensure system is disabled when audit logs are full - 'admin_space_left_action'UnixCIS Amazon Linux v2.1.0 L2
4.1.1.2 Ensure system is disabled when audit logs are full - 'admin_space_left_action'UnixCIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0
4.1.1.2 Ensure system is disabled when audit logs are full - 'admin_space_left_action'UnixCIS Ubuntu Linux 14.04 LTS Workstation L2 v2.1.0
4.1.1.2 Ensure system is disabled when audit logs are full - 'space_left_action is configured'UnixCIS Amazon Linux v2.1.0 L2
4.1.1.2 Ensure system is disabled when audit logs are full - 'space_left_action'UnixCIS Ubuntu Linux 14.04 LTS Workstation L2 v2.1.0
4.1.1.2 Ensure system is disabled when audit logs are full - 'space_left_action'UnixCIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0
4.1.1.3 Ensure audit logs are not automatically deletedUnixCIS Ubuntu Linux 14.04 LTS Workstation L2 v2.1.0
4.1.1.3 Ensure audit logs are not automatically deletedUnixCIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0
4.1.2.4 Ensure system notification is sent out when volume is 75% full - SA and Information System Security Officer ISSO, at a minimum, when allocated audit record storage volume reaches 75% of the repository maximum audit record storage capacity.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.2.5 Ensure system is disabled when audit logs are full - at a minimum via email when the threshold for the repository maximum audit record storage capacity is reached.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.2.5 Ensure system is disabled when audit logs are full - at a minimum when the threshold for the repository maximum audit record storage capacity is reached.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.9 Enable Kernel Level Auditing, Check if 'minfree:20' is set in /etc/security/audit_control.UnixCIS Solaris 10 L1 v5.2
8.1.1.2 Disable System on Audit Log Full - 'action_mail_acct is configured'UnixCIS Ubuntu 12.04 LTS Benchmark L2 v1.1.0
8.1.1.2 Disable System on Audit Log Full - 'admin_space_left_action = halt'UnixCIS Ubuntu 12.04 LTS Benchmark L2 v1.1.0
8.1.1.2 Disable System on Audit Log Full - action_mail_acct = rootUnixCIS Debian Linux 7 L2 v1.0.0
8.1.1.2 Disable System on Audit Log Full - admin_space_left_action = haltUnixCIS Debian Linux 7 L2 v1.0.0
8.1.1.2 Disable System on Audit Log Full - space_left_action = emailUnixCIS Debian Linux 7 L2 v1.0.0
8.1.1.2 Disable System on Audit Log Full- 'space_left_action = email'UnixCIS Ubuntu 12.04 LTS Benchmark L2 v1.1.0
8.1.1.3 Keep All Auditing InformationUnixCIS Ubuntu 12.04 LTS Benchmark L2 v1.1.0
ALMA-09-053260 - AlmaLinux OS 9 must take action when allocated audit record storage volume reaches 95 percent of the audit record storage capacity.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-053370 - AlmaLinux OS 9 must take action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-053480 - AlmaLinux OS 9 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-053590 - AlmaLinux OS 9 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent usage.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
AOSX-13-000310 - The macOS system must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-001031 - The macOS system must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-15-001031 - The macOS system must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.UnixDISA STIG Apple Mac OSX 10.15 v1r10
APPL-11-001031 - The macOS system must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.UnixDISA STIG Apple macOS 11 v1r5
APPL-11-001031 - The macOS system must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.UnixDISA STIG Apple macOS 11 v1r8
APPL-12-001031 - The macOS system must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.UnixDISA STIG Apple macOS 12 v1r9
APPL-13-001031 - The macOS system must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.UnixDISA STIG Apple macOS 13 v1r5
APPL-14-001030 The macOS system must configure audit capacity warning.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-001031 The macOS system must configure audit failure notification.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-15-001030 - The macOS system must configure audit capacity warning.UnixDISA Apple macOS 15 (Sequoia) STIG v1r4
APPL-15-001031 - The macOS system must configure audit failure notification.UnixDISA Apple macOS 15 (Sequoia) STIG v1r4