STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 1 hour ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to IBM AIX 7.x Security Technical Implementation Guide

V-215239

CAT II (Medium)

AIX must produce audit records containing information to establish the outcome of the events.

Rule ID

SV-215239r958420_rule

STIG

IBM AIX 7.x Security Technical Implementation Guide

Version

V3R2

CCIs

CCI-000134

Discussion

Without information about the outcome of events, security personnel cannot make an accurate assessment as to whether an attack was successful or if changes were made to the security state of the system. Event outcomes can include indicators of event success or failure and event-specific results (e.g., the security state of the information system after the event occurred). As such, they also provide a means to measure the impact of an event and help authorized personnel to determine the appropriate response.

Check Content

Verify the audit event "status" is displayed:

The log file can be set by the "trail" variable in /etc/security/audit/config.

# grep trail /etc/security/audit/config
        trail = /audit/trail

Note: The default log file is /audit/trail.

Use the following command to display the audit events:

# /usr/sbin/auditpr -i <audit log file> -helRtcp 

event           login    status      time                     command           
              process  
--------------- -------- ----------- ------------------------ ------------------
------------- -------- 
PROC_Delete     root     OK          Wed Oct 31 23:01:37 2018 audit             
              9437656  
FILE_Close      root     OK          Wed Oct 31 23:01:37 2018 auditbin          
              12255562 
FILE_Open       root     OK          Wed Oct 31 23:01:37 2018 auditbin          
              12255562 
FILE_Read       root     OK          Wed Oct 31 23:01:37 2018 auditbin          
              12255562 
FILE_Close      root     OK          Wed Oct 31 23:01:37 2018 auditbin          
              12255562 
PROC_Create     root     OK          Wed Oct 31 23:01:44 2018 ksh               
              12976466 
FILE_Close      root     OK          Wed Oct 31 23:01:44 2018 ksh               
              9437658  
FILE_Open       root     OK          Wed Oct 31 23:01:44 2018 ksh               
              9437658  
FILE_Read       root     OK          Wed Oct 31 23:01:44 2018 ksh               
              9437658  
FILE_Close      root     OK          Wed Oct 31 23:01:44 2018 ksh               
              9437658  
PROC_Execute    root     OK          Wed Oct 31 23:01:44 2018 ls                
              9437658  
FILE_Open       root     OK          Wed Oct 31 23:01:44 2018 ls                
              9437658  

If audit status is not displayed, this is a finding.

More information on the command options used above:
            -e the audit event.
            -l the login name of the user.
            -R the audit status.
            -t the time the record was written.
            -c the command name.
            -p the process ID.

Fix Text

Reset the audit system with the following command:
# /usr/sbin/audit shutdown

Start the audit system with the following command:
# /usr/sbin/audit start