Compliance means proving that systems meet a defined standard, whether an internal policy, an industry framework or a regulation. Auditing supplies the evidence: records of who did what and when, and proof that the configuration matches the standard. As a Linux administrator you configure these tools, respond to what they find and produce reports for auditors. The four pieces here work together: auditd records events, log review turns records into findings, vulnerability scanning finds known weaknesses, and benchmarks define what a good configuration looks like.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.