1. Home
  2. Security Hardening
  3. CIS Apple MacOS 12.0 Monterey V1.0.0 L2
  4. Ensure Security Auditing Flags Are Configured Per Local Organizational Requirements

Ensure Security Auditing Flags Are Configured Per Local Organizational Requirements

Details

Auditing is the capture and maintenance of information about security-related events. Auditable events often depend on differing organizational requirements.

Rationale:

Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises or attacks that have occurred, have begun, or are about to begin. Audit logs are necessary to provide a trail of evidence in case the system or network is compromised.

Depending on the governing authority, organizations can have vastly different auditing requirements. In this control we have selected a minimal set of audit flags that should be a part of any organizational requirements. The flags selected below may not adequately meet organizational requirements for users of this benchmark. The auditing checks for the flags proposed here will not impact additional flags that are selected.

Solution

Perform the following to set the require Security Auditing Flags:
Edit the /etc/security/audit_control file and add fm, ad, -ex, aa, -fr, lo, and -fw flags or add -all to flags.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Audit and Accountability, System and Information Integrity.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles