|Platform: macosx10.10||Date: (C)2015-06-23 (M)2018-03-17|
Audit Successful and Unsuccessful Attempts to Gain Privileged Access
Frequently, an attacker that successfully gains access to a system has only gained access to an account with limited privileges, such as a guest account or a service account. The attacker must attempt to change to another user account with normal or elevated privileges in order to proceed. Auditing successful and unsuccessful attempts to elevate privileges mitigates this risk.
EXISTS/DOES NOT EXIST
The options to configure the audit daemon are located in the /etc/security/audit_control file. To view the current settings, run the following command:
sudo grep ^flags /etc/security/audit_control
If the 'lo', 'ad', and 'aa' options are not set, this is a finding.
|SCAP Repo OVAL Definition||oval:org.secpod.oval:def:25061|