Skip to content

The Photon operating system must initiate auditing as part of the boot process.

An XCCDF Rule

Description

<VulnDiscussion>Each process on the system carries an "auditable" flag, which indicates whether its activities can be audited. Although auditd takes care of enabling this for all processes that launch after it starts, adding the kernel argument ensures the flag is set at boot for every process on the system. This includes processes created before auditd starts.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-256521r887237_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Navigate to and open:

/boot/grub2/grub.cfg

Locate the boot command line arguments. An example follows: