Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-222464 | APSC-DV-000850 | SV-222464r879876_rule | Medium |
Description |
---|
Knowing when a user’s application session began and when it ended is critical information that aids in forensic analysis. |
STIG | Date |
---|---|
Application Security and Development Security Technical Implementation Guide | 2023-06-08 |
Check Text ( C-24134r493300_chk ) |
---|
Review and monitor the application logs. Initiate a user session and observe if the log includes a time stamp showing the start of the session. Terminate the user session and observe if the log includes a time stamp showing the end of the session. If the start and the end time of the session are not recorded in the logs, this is a finding. |
Fix Text (F-24123r493301_fix) |
---|
Configure the application or application server to record the start and end time of user session activity. |