Rule ID
SV-202029r960888_rule
Version
V5R4
CCIs
CCI-001464
If auditing is enabled late in the startup process, the actions of some start-up processes may not be audited. Some audit systems also maintain state information only available if auditing is enabled before a given process is created.
Determine if the network device initiates session auditing upon startup. This requirement may be verified by validated test results. If the network device does not initiate session auditing upon startup, this is a finding.
Configure the network device to initiate session auditing upon startup.