The operating system must generate audit records containing the full-text recording of privileged commands.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-203609
SRG-OS-000042-GPOS-00020
SV-203609r958422_rule
Medium
Description
Reconstruction of harmful events or forensic analysis is not possible if audit records do not contain enough information.
At a minimum, the organization must audit the full-text recording of privileged commands. The organization must maintain audit trails in sufficient detail to reconstruct events to determine the cause and impact of compromise.