Ensure successful and unsuccessful attempts to use the setfacl command are recordedID: oval:org.secpod.oval:def:95964 | Date: (C)2023-12-19 (M)2023-12-20 |
Class: COMPLIANCE | Family: unix |
The operating system must generate audit records for successful/unsuccessful uses of the setfacl command. Rationale:This utility sets Access Control Lists (ACLs) of files and directories. Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one.