1+ # NIST 800-53 AU Family: Audit and Accountability
12controls :
23 - id : au-1
34 title : Policy and Procedures
@@ -62,6 +63,7 @@ controls:
6263 levels :
6364 - low
6465 rules :
66+ - audit_rules_login_events_faillog
6567 - audit_rules_privileged_commands_chfn
6668 - auditd_log_format
6769 - auditd_name_format
@@ -72,6 +74,11 @@ controls:
7274 levels :
7375 - moderate
7476 rules :
77+ - audit_rules_etc_cron_d
78+ - audit_rules_networkconfig_modification_etc_hosts
79+ - audit_rules_networkconfig_modification_etc_issue
80+ - audit_rules_networkconfig_modification_etc_issue_net
81+ - audit_rules_networkconfig_modification_etc_networkmanager_system_connections
7582 - audit_rules_privileged_commands_insmod
7683 - audit_rules_privileged_commands_kmod
7784 - audit_rules_privileged_commands_modprobe
@@ -111,6 +118,8 @@ controls:
111118 levels :
112119 - low
113120 rules :
121+ - audit_rules_continue_loading
122+ - audit_rules_enable_syscall_auditing
114123 - audit_rules_system_shutdown
115124 - postfix_client_configure_mail_alias_postmaster
116125 status : automated
@@ -292,6 +301,9 @@ controls:
292301 levels :
293302 - low
294303 rules :
304+ - audit_rules_immutable_login_uids
305+ - audit_rules_mac_modification_etc_apparmor
306+ - audit_rules_mac_modification_etc_apparmor_d
295307 - directory_permissions_var_log_audit
296308 - file_audit_tools_group_ownership
297309 - file_audit_tools_ownership
@@ -409,12 +421,19 @@ controls:
409421 - audit_rules_dac_modification_lsetxattr
410422 - audit_rules_dac_modification_removexattr
411423 - audit_rules_dac_modification_setxattr
424+ - audit_rules_dac_modification_umount
425+ - audit_rules_dac_modification_umount2
426+ - audit_rules_execution_chacl
412427 - audit_rules_execution_chcon
428+ - audit_rules_execution_chmod
429+ - audit_rules_execution_rm
430+ - audit_rules_execution_setfacl
413431 - audit_rules_file_deletion_events_rename
414432 - audit_rules_file_deletion_events_renameat
415433 - audit_rules_file_deletion_events_renameat2
416434 - audit_rules_file_deletion_events_unlink
417435 - audit_rules_file_deletion_events_unlinkat
436+ - audit_rules_kernel_module_loading_create
418437 - audit_rules_kernel_module_loading_delete
419438 - audit_rules_kernel_module_loading_finit
420439 - audit_rules_kernel_module_loading_init
0 commit comments