Standard users should not be able to view or alter audit files. The audit trail (that is, the audit files) should be accessed only with the onshowaudit utility, which has its own protection, as follows:
The following characteristics control access to audit files in a UNIX environment and protect them from being accidentally read or destroyed:
The following examples show the security configuration for UNIX audit files with no role separation:
aaodir
aaodir/adtcfg.std
The following examples show the UNIX security configuration with role separation:
aaodir
aaodir/adtcfg.std
The following characteristics control access to the Windows audit file and protect it from accidental viewing or deletion:
The following examples show how to control access to the Windows audit file:
aaodir
aaodir\adtcfg.std