What it means
The Linux Audit Framework records security-relevant system calls, identity activity, object access, and policy events according to rules designed for investigation and accountability.
Why it matters
General logs often explain application behavior, while audit records are designed to answer who performed a protected action and under which identity context.
Practical focus
- Define the privileged actions and protected objects that require audit evidence and the events that require attention
- Configure risk-based audit rules, protected configuration, and centralized collection with consistent ownership and change records
- Validate rule coverage, event completeness, time synchronization, and storage pressure for coverage, integrity, and operational usefulness
- Rehearse audit overload, missing events, or local evidence being altered so response steps do not depend on improvisation
Common mistakes
- Collecting signals without defining a response decision
- Assuming successful configuration means sustained coverage
- Keeping evidence on the same failure path as the protected service
- Waiting for audit overload, missing events, or local evidence being altered before testing detection and recovery
Certification relevance
This subject appears in or supports the following certification bodies of knowledge: