The HYCU virtual appliance must generate log records for a locally developed list of auditable events.
An XCCDF Rule
Description
Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. Audit records can be generated from various components within the network device (e.g., module or policy filter).
- ID
- SV-268244r1038775_rule
- Version
- HYCU-ND-000280
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the operating system to use a locally developed list of auditable events by editing "/etc/audit/auditd.conf" files using the following command:
sudo vi /etc/audit/auditd.conf
Add or modify lines to have the required values for the organization.