STIGUI
V-282599CAT II — Medium severitySV-282599r1201494_rule

TOSS 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog.

Rule version TOSS-05-000461 · STIG v1 · 2026-08-20

Discussion

Without generating audit records specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one.

Satisfies: SRG-OS-000392-GPOS-00172, SRG-OS-000477-GPOS-00222

Check

Verify TOSS 5 generates audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/tallylog" using the following command:

$ sudo auditctl -l | grep /var/log/tallylog

-w /var/log/tallylog -p wa -k logins

If the command does not return a line, or the line is commented out, this is a finding.

Fix

Configure TOSS 5 to generate audit records for all account creations, modifications, disabling, and termination events that affect "/var/log/tallylog".

Add or update the following file system rule to "/etc/audit/rules.d/audit.rules":

-w /var/log/tallylog -p wa -k logins

Restart the audit daemon for the changes to take effect.

Identifiers

Group ID
V-282599
Group title
SRG-OS-000392-GPOS-00172
Rule ID
SV-282599r1201494_rule
Check ID
C-87160r1201493_chk
Fix ID
F-87065r1200776_fix