Configure audit to meet requirements for Operating System Protection Profile (OSPP) v4.2.1.
Audit defines groups of rules in /usr/share/doc/audit/rules
to satisfy specific policies.
To fulfill requirements for compliance with OSPP v4.2.1, the following files are necessary:
- /usr/share/doc/audit-VERSION/rules/10-base-config.rules
- /usr/share/doc/audit-VERSION/rules/11-loginuid.rules
- /usr/share/doc/audit-VERSION/rules/30-ospp-v42.rules
- /usr/share/doc/audit-VERSION/rules/43-module-load.rules
Copy the files from /usr/share/doc/audit/rules
to /etc/audit/rules.d
:
cp /usr/share/doc/audit*/rules/{10-base-config,11-loginuid,30-ospp-v42,43-module-load}.rules /etc/audit/rules.d/