Configuring Audit Settings for STIG Compliance on Red Hat

30 minutes
  • 2 Learning Objectives

About this Hands-on Lab

The Red Hat Linux audit service comes with precompiled rule sets for various compliance requirements. In this lab, we will configure a Red Hat host’s audit rules to include the STIG (Security Technical Implementation Guide) compliance rule set. This will allow us to identify any points at which we are not compliant with STIG requirements.

Learning Objectives

Successfully complete this lab by achieving the following learning objectives:

Implement the Red Hat included STIG audit rules
  1. SSH into the host and switch to root via sudo su

  2. Make a backup of the current audit rules using the following command:

    cp /etc/audit/rules.d/audit.rules /etc/audit/rules.d/audit.rules_backup
  3. Copy the STIG audit rules into the audit.rules file with the following command:

    cd /usr/share/doc/audit-2.8.1/rules
    cat 30-stig.rules 99-finalize.rules >> /etc/audit/rules.d/audit.rules
    y (accept to overwrite file)
Restart the auditd service
  1. To restart the auditd service, use the following command:

    sudo service auditd restart  
  2. Run the following command to verify the status is active (running):

    service auditd status

Additional Resources

Your organization wants to start bidding for government contracts and must be STIG (Security Technical Implementation Guideline) compliant before doing any work for the government. In order to move forward with this, you have been tasked with enabling STIG compliant audit rules on a Red Hat server as a testbed. You will need to ensure all STIG compliant rules remain persistent across reboots.

What are Hands-on Labs

Hands-on Labs are real environments created by industry experts to help you learn. These environments help you gain knowledge and experience, practice without compromising your system, test without risk, destroy without fear, and let you learn from your mistakes. Hands-on Labs: practice your skills before delivering in the real world.

Sign In
Welcome Back!

Psst…this one if you’ve been moved to ACG!

Get Started
Who’s going to be learning?