The operating system must provide the capability to automatically process audit records for events of interest based upon selectable, event criteria.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-216249SOL-11.1-010080SV-216249r958430_ruleCCI-000158medium
Description
Without an audit reporting capability, users find it difficult to identify specific patterns of attack.
STIGDate
Solaris 11 SPARC Security Technical Implementation Guide2025-05-05

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
  • DISA · 3 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-000158
1.00
  • DISA · 3 · disa_xccdf · related

Details

Check Text (C-216249r958430_chk)

The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.

Fix Text (F-17483r370836_fix)

The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s