UCF STIG Viewer Logo

The application server must provide audit record generation capability for defined auditable events.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35141 SRG-APP-000089-AS-000050 SV-46428r1_rule Low
Description
Audit records can be generated from various components within the application server (e.g. , httpd, beans, etc.). From an application perspective, certain specific application functionalities may be audited as well. The list of audited events is the set of events for which audits are to be generated. This set of events is typically a subset of the list of all events for which the system is capable of generating audit records (e.g., auditable events, time stamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, filenames involved, and access control or flow control rules invoked). Application servers must be able to set the log level which controls what type of information and the degree to which the application server logs data.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43528r1_chk )
Review AS product documentation and server configuration to determine if the system generates audit records for definable events (e.g., INFO, DEBUG, FATAL, ALL). Perform functionality testing and examine log data to ensure defined events are logged. If the system cannot perform this function, this is a finding.
Fix Text (F-39692r1_fix)
Configure the AS to audit at the defined event level.