Audit Settings
Swisscom performs the audit settings defined in the below chapter (File System Layout Managed RHEL)[#file-system-layout-managed-rhel]. The user may not change these settings (e.g. Full Managed mode). Swisscom uses the compliance checks to check whether the settings are set accordingly.
Audit Settings Managed Windows
Category | SubcategorySub | Setting |
---|
System | Security System Extension | Failure |
| System Integrity | Failure |
| IPsec Driver | Failure |
| Other System Events | Failure |
| Security State Change | Failure |
Logon/Logoff | Logon | Success and Failure |
| Logoff | Success and Failure |
| Account Lockout | Success and Failure |
| IPsec Main Mode | Success and Failure |
| IPsec Quick Mode | Success and Failure |
| IPsec Extended Mode | Success and Failure |
| Special Logon | Success and Failure |
| Other Logon/Logoff Events | Success and Failure |
| Network Policy Server | Success and Failure |
| User / Device Claims | Success and Failure |
Object Access | File System | No Auditing |
| Registry | No Auditing |
| Kernel Object | No Auditing |
| SAM | No Auditing |
| Certification Services | No Auditing |
| Application Generated | No Auditing |
| Handle Manipulation | No Auditing |
| File Share | No Auditing |
| Filtering Platform Packet Drop | No Auditing |
| Filtering Platform Connection | No Auditing |
| Other Object Access Events | No Auditing |
| Detailed File Share | No Auditing |
| Removable Storage | No Auditing |
| Central Policy Staging | No Auditing |
Privilege Use | Non Sensitive Privilege Use | Success and Failure |
| Other Privilege Use Events | Success and Failure |
| Sensitive Privilege Use | Success and Failure |
Detailed Tracking | Process Creation | No Auditing |
| Process Termination | No Auditing |
| DPAPI Activity | No Auditing |
| RPC Events | No Auditing |
Policy Change | Authentication Policy Change | Success and Failure |
| Authorization Policy Change | Success and Failure |
| MPSSVC Rule-Level Policy Change | Success and Failure |
| Filtering Platform Policy Change | Success and Failure |
| Other Policy Change Events | Success and Failure |
| Audit Policy Change | Success and Failure |
Account Management | User Account Management | Success and Failure |
| Computer Account Management | Success and Failure |
| Security Group Management | Success and Failure |
| Distribution Group Management | Success and Failure |
| Application Group Management | Success and Failure |
| Other Account Management Events | Success and Failure |
DS Access | Directory Service Changes | No Auditing |
| Directory Service Replication | No Auditing |
| Detailed Directory Service Replication | No Auditing |
| Directory Service Access | Success |
Account Logon | Kerberos Service Ticket Operations | Success and Failure |
| Other Account Logon Events | Success and Failure |
| Kerberos Authentication Service | Success and Failure |
| Credential Validation | Success and Failure |
File System Layout Managed RHEL
Filesystem | Function |
---|
/ | Directory which contains the necessary files to boot the system |
/boot | Directory for the static files of the bootloader |
/home | Directory for user homes |
/tmp | Directory for temporary files |
/opt | Directory for additionally installable programs, mostly large packages or commercial software |
/var/log | Directory for log files |
/var/log/audit | Directory for auditing service log files |
/usr/local | Directory for self-compiled programs |
/opt/ds_agent | Directory for malware protection |