UCF STIG Viewer Logo

The application server must provide automated mechanisms that can be used to alert security personnel of inappropriate or unusual activities with security implications.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35431 SRG-APP-000237-AS-000161 SV-46718r1_rule Medium
Description
Manual notification procedures do not offer the reliability and speed of an automated notification solution. Application servers must utilize automated mechanisms to alert security personnel of inappropriate or unusual activities that have security implications. If this capability is not built directly into the application server, the application server must be able to integrate with existing security infrastructure that provides this capability.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43782r1_chk )
Review the AS documentation to determine if the AS provides automated mechanisms for alerting personnel of inappropriate or unusual activities with security implications. If this capability is not built directly into the application server, or the application server does not integrate with existing security infrastructure that provides this capability, this is a finding.
Fix Text (F-39975r1_fix)
Configure the AS to automatically alert security personnel when unusual or security-related events occur.