linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* CIS and audit rules
@ 2015-08-28 20:12 Alarie, Maxime
  2015-09-02 23:01 ` John Jasen
  0 siblings, 1 reply; 2+ messages in thread
From: Alarie, Maxime @ 2015-08-28 20:12 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 295 bytes --]


Anyone ever implemented auditd  by following the CIS standards described here?  https://benchmarks.cisecurity.org/downloads/show-single/?file=suse11.110

Is it too restrictive?  Not enough?  Too much ressources consuming?  I would like some comments/opinions if possible.


Many thanks.

[-- Attachment #1.2: Type: text/html, Size: 2442 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: CIS and audit rules
  2015-08-28 20:12 CIS and audit rules Alarie, Maxime
@ 2015-09-02 23:01 ` John Jasen
  0 siblings, 0 replies; 2+ messages in thread
From: John Jasen @ 2015-09-02 23:01 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 844 bytes --]

I've been testing a variant of the CIS benchmarks, supplemented (for
compliance reasons) by the NIST USGCB baselines.

I've also been testing auditd with setuid/setgid binaries.

Also as a potential replacement for aide (again, mostly compliance reasons).

Your use of auditd rules depends a lot on your drivers for doing so, and
your desired results.


On 08/28/2015 04:12 PM, Alarie, Maxime wrote:
>
>  
>
> Anyone ever implemented auditd  by following the CIS standards
> described here?
>  https://benchmarks.cisecurity.org/downloads/show-single/?file=suse11.110
>
>  
>
> Is it too restrictive?  Not enough?  Too much ressources consuming?  I
> would like some comments/opinions if possible.
>
>  
>
>  
>
> Many thanks.
>
>
>
> --
> Linux-audit mailing list
> Linux-audit@redhat.com
> https://www.redhat.com/mailman/listinfo/linux-audit


[-- Attachment #1.2: Type: text/html, Size: 3639 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2015-09-02 23:01 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-08-28 20:12 CIS and audit rules Alarie, Maxime
2015-09-02 23:01 ` John Jasen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).