[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99536

 
 

909

 
 

80128

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-90268-4

Platform: macosx10.10Date: (C)2015-06-23   (M)2017-11-22



Audit Account Creation Once an attacker establishes initial access to a system, the attacker often attempts to create a persistent method of re-establishing access. One way to accomplish this is for the attacker to create a new account. Auditing of account creation mitigates this risk. To address access requirements, many operating systems may be integrated with enterprise level authentication/access/auditing mechanisms that meet or exceed access control policy requirements.


Parameter: EXISTS/DOES NOT EXIST


Technical Mechanism: In order to view the currently configured flags for the audit daemon, run the following command: sudo grep ^flags /etc/security/audit_control The account creation events are logged by way of the 'ad' flag. If 'ad' is not listed in the result of the check, this is a finding

References:

Resource IdReference
NISTAC-2 (4)
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:25045


OVAL    1
oval:org.secpod.oval:def:25045
XCCDF    1
xccdf_org.secpod_benchmark_general_Mac_OS_X_10_10

© 2013 SecPod Technologies