The operating system must initiate session audits at system start-up.

STIG ID: SRG-OS-000254-GPOS-00095  |  SRG: SRG-OS-000254 |  Severity: medium |  CCI: CCI-001464 |  Vulnerability Id: V-203670 | 

Vulnerability Discussion

If auditing is enabled late in the start-up process, the actions of some start-up processes may not be audited. Some audit systems also maintain state information only available if auditing is enabled before a given process is created.

Check

Verify the operating system initiates session audits at system start-up. If it does not, this is a finding.

Fix

Configure the operating system to initiate session audits at system start-up.