UCF STIG Viewer Logo

AIX audit logs must be rotated daily.


Overview

Finding ID Version Rule ID IA Controls Severity
V-215256 AIX7-00-002057 SV-215256r508663_rule Medium
Description
Rotate audit logs daily to preserve audit file system space and to conform to the DoD/DISA requirement. If it is not rotated daily and moved to another location, then there is more of a chance for the compromise of audit data by malicious users.
STIG Date
IBM AIX 7.x Security Technical Implementation Guide 2022-06-06

Details

Check Text ( C-16454r294219_chk )
Check for any "crontab" entries that rotate audit logs:

# crontab -l
30 23 * * * /root/logrotate.sh #Daily log rotation script
If such a cron job is found, this is not a finding.

Otherwise, query the SA.

If there is a process automatically rotating audit logs, this is not a finding.

If the SA manually rotates audit logs, this is a finding.

If the audit output is not archived daily, to tape or disk, this is a finding.

Review the audit log directory.

If more than one file is there, or if the file does not have today's date, this is a finding.
Fix Text (F-16452r294220_fix)
Configure a cron job or other automated process to rotate the audit logs on a daily basis.