[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99602

 
 

909

 
 

80170

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-90003-5

Platform: macosx10.9Date: (C)2015-06-11   (M)2017-11-22



Audit Account Creation Once an attacker establishes initial access to a system, the attacker often attempts to create a persistent method of re-establishing access. One way to accomplish this is for the attacker to create a new account. Auditing of account creation mitigates this risk. To address access requirements, many operating systems may be integrated with enterprise level authentication/access/auditing mechanisms that meet or exceed access control policy requirements.


Parameter: EXISTS/DOES NOT EXIST


Technical Mechanism: In order to view the currently configured flags for the audit daemon, run the following command: sudo grep ^flags /etc/security/audit_control The account creation events are logged by way of the 'ad' flag. If 'ad' is not listed in the result of the check, this is a finding

References:

Resource IdReference
NISTAC-2 (4)
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:24637


OVAL    1
oval:org.secpod.oval:def:24637
XCCDF    1
xccdf_org.secpod_benchmark_general_Mac_OS_X_10_9

© 2013 SecPod Technologies