Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35182 | SRG-APP-000100-AS-000063 | SV-46469r1_rule | Medium |
Description |
---|
Information system auditing capability is critical for accurate forensic analysis. Audit record content that may be necessary to satisfy the requirement of this control, includes: time stamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, filenames involved, and access control or flow control rules invoked. Application servers have differing levels of logging capabilities which can be specified by setting a verbosity level. The application server must, at a minimum, be capable of establishing the identity of any user or process that is associated with any particular event. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43562r1_chk ) |
---|
Review AS documentation and the audit logs on the AS to determine if the logs contain information that establishes the identity of the user or process associated with audit event data. If the AS does not produce logs that establish the identity of the user or process associated with audit event data, this is a finding. |
Fix Text (F-39730r1_fix) |
---|
Configure the AS auditing system to log the identity of the user or process related to audit events. |