[Forgot Password]
Login  Register Subscribe

24436

 
 

131815

 
 

116564

 
 

909

 
 

91325

 
 

141

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-90268-4

Platform: macosx10.10Date: (C)2015-06-23   (M)2018-04-04



Audit Account Creation Once an attacker establishes initial access to a system, the attacker often attempts to create a persistent method of re-establishing access. One way to accomplish this is for the attacker to create a new account. Auditing of account creation mitigates this risk. To address access requirements, many operating systems may be integrated with enterprise level authentication/access/auditing mechanisms that meet or exceed access control policy requirements.


Parameter: EXISTS/DOES NOT EXIST


Technical Mechanism: In order to view the currently configured flags for the audit daemon, run the following command: sudo grep ^flags /etc/security/audit_control The account creation events are logged by way of the 'ad' flag. If 'ad' is not listed in the result of the check, this is a finding

References:

Resource IdReference
NISTAC-2 (4)
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:25045


OVAL    1
oval:org.secpod.oval:def:25045
XCCDF    2
xccdf_org.secpod_benchmark_general_Mac_OS_X_10_10
xccdf_org.secpod_benchmark_SecPod_MAC_OS_X_10_10

© SecPod Technologies