[Forgot Password]
Login  Register Subscribe

24003

 
 

131573

 
 

108530

 
 

909

 
 

85343

 
 

134

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-90286-6

Platform: macosx10.10Date: (C)2015-06-23   (M)2018-03-17



Audit Successful and Unsuccessful Logon Attempts An attacker might attempt to log in as an authorized user, through stolen credentials, unpatched exploits, or brute force attempts to guess a valid username and password. If a user is attempting to log in to a system at an unusual time, or if there are many failed attempts, there is a possibility that the system is the target of an attack. Auditing logon events mitigates this risk by recording all logon attempts, successful and unsuccessful, to the system.


Parameter: EXISTS/DOES NOT EXIST


Technical Mechanism: In order to view the currently configured flags for the audit daemon, run the following command: sudo grep ^flags /etc/security/audit_control Logon events are logged by way of the 'aa' flag. If 'aa' is not listed in the result of the check, this is a finding.

References:

Resource IdReference
NISTAU-12 c
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:25063


OVAL    1
oval:org.secpod.oval:def:25063
XCCDF    1
xccdf_org.secpod_benchmark_general_Mac_OS_X_10_10

© SecPod Technologies