Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35447 | SRG-APP-000292-AS-000176 | SV-46734r1_rule | Medium |
Description |
---|
Once an attacker establishes initial access to a system, they often attempt to create a persistent method of re-establishing access. One way to accomplish this is for the attacker to simply modify or copy an existing account. Application servers provide either a local user store or they integrate with enterprise user stores like LDAP or Active Directory. When the AS is the authoritative user store, the application server must be able to notify designated individuals when new accounts are modified. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43801r1_chk ) |
---|
Review AS product documentation and server configuration to determine if the AS is configured to notify staff when accounts are modified. If the AS is not configured to meet this requirement, this is a finding. |
Fix Text (F-39991r1_fix) |
---|
Configure the AS to automatically notify appropriate personnel when accounts are modified. |