* CIS and audit rules
@ 2015-08-28 20:12 Alarie, Maxime
2015-09-02 23:01 ` John Jasen
0 siblings, 1 reply; 2+ messages in thread
From: Alarie, Maxime @ 2015-08-28 20:12 UTC (permalink / raw)
To: linux-audit@redhat.com
[-- Attachment #1.1: Type: text/plain, Size: 295 bytes --]
Anyone ever implemented auditd by following the CIS standards described here? https://benchmarks.cisecurity.org/downloads/show-single/?file=suse11.110
Is it too restrictive? Not enough? Too much ressources consuming? I would like some comments/opinions if possible.
Many thanks.
[-- Attachment #1.2: Type: text/html, Size: 2442 bytes --]
[-- Attachment #2: Type: text/plain, Size: 0 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: CIS and audit rules
2015-08-28 20:12 CIS and audit rules Alarie, Maxime
@ 2015-09-02 23:01 ` John Jasen
0 siblings, 0 replies; 2+ messages in thread
From: John Jasen @ 2015-09-02 23:01 UTC (permalink / raw)
To: linux-audit
[-- Attachment #1.1: Type: text/plain, Size: 844 bytes --]
I've been testing a variant of the CIS benchmarks, supplemented (for
compliance reasons) by the NIST USGCB baselines.
I've also been testing auditd with setuid/setgid binaries.
Also as a potential replacement for aide (again, mostly compliance reasons).
Your use of auditd rules depends a lot on your drivers for doing so, and
your desired results.
On 08/28/2015 04:12 PM, Alarie, Maxime wrote:
>
>
>
> Anyone ever implemented auditd by following the CIS standards
> described here?
> https://benchmarks.cisecurity.org/downloads/show-single/?file=suse11.110
>
>
>
> Is it too restrictive? Not enough? Too much ressources consuming? I
> would like some comments/opinions if possible.
>
>
>
>
>
> Many thanks.
>
>
>
> --
> Linux-audit mailing list
> Linux-audit@redhat.com
> https://www.redhat.com/mailman/listinfo/linux-audit
[-- Attachment #1.2: Type: text/html, Size: 3639 bytes --]
[-- Attachment #2: Type: text/plain, Size: 0 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2015-09-02 23:01 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-08-28 20:12 CIS and audit rules Alarie, Maxime
2015-09-02 23:01 ` John Jasen
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).