Unauthorized disclosure of audit records can reveal system and configuration data to attackers, thus compromising its confidentiality.
Audit information includes all information (e.g., audit records, audit settings, audit reports) needed to successfully audit operating system activity.
Using the directory where the audit log file is located, check if the audit log directory has a mode of "0700" or less permissive with the following command: