Important steps in a UNIX security audit

Checking the distribution as you run as to which packages to install, and whether they are on the CD, or however you installed. Now that we’ve checked out /etc/password and verified that only the users that are necessary for operation (assuming anonymous FTP is disabled, as well as the http). After checking the security state of the system, starting with routine examination of the log files, these are usually found in /usr/adm or /var/logs, after tracking system loads using the program top.