1. Home
  2. Security Hardening
  3. DISA STIG Solaris 10 X86 V2R2
  4. GEN000000-SOL00040 – The /etc/security/audit_user file must not define a different auditing level for specific users.

GEN000000-SOL00040 – The /etc/security/audit_user file must not define a different auditing level for specific users.

Details

The audit_user file may be used to selectively audit more, or fewer, auditing features for specific individuals. If used this way it could subject the activity to a lawsuit and could cause the loss of valuable auditing data in the case of a system compromise. If an item is audited for one individual (other than for root and administrative users – who have more auditing features) it must be audited for all.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Edit the audit_user file and remove specific user configurations differing from the global audit settings.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Audit and Accountability.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles