This is not the latest version of the STIG. This is provided for archival purposes. See the latest STIG.
The Red Hat Enterprise Linux operating system must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited.
If the value of the "enable_krb5" option is not set to "yes" or the line is commented out, ask the System Administrator to indicate how the audit logs are off-loaded to a different system or media.
If there is no evidence that the transfer of the audit logs being off-loaded to another system or media is encrypted, this is a finding.
Fix
Configure the operating system to encrypt the transfer of off-loaded audit records onto a different system or media from the system being audited.
Uncomment the "enable_krb5" option in "/etc/audisp/audisp-remote.conf" and set it with the following line: