UCF STIG Viewer Logo

ColdFusion must send log records to the operating system logging facility.


Overview

Finding ID Version Rule ID IA Controls Severity
V-62385 CF11-02-000057 SV-76875r1_rule Medium
Description
Protection of log data includes assuring log data is not accidentally lost or deleted. By sending some of the log messages to the operating system logging facilities, these log messages become part of the OS log history, become part of the log review performed by the OS administrator, and become part of the backup of OS log data. Note: This feature is only available for Linux installations.
STIG Date
Adobe ColdFusion 11 Security Technical Implementation Guide 2017-12-31

Details

Check Text ( C-63189r1_chk )
This feature is not present when ColdFusion is installed on Windows; therefore, this finding is not applicable.

Within the Administrator Console, navigate to the "Logging Settings" page under the "Debugging & Logging" menu.

If "Use operating system logging facilities" is not checked, this is a finding.
Fix Text (F-68305r1_fix)
Navigate to the "Logging Settings" page under the "Debugging & Logging" menu. Check "Use operating system logging facilities" and select the "Submit Changes" button.