UCF STIG Viewer Logo

The DBMS must provide the capability to capture, record, and log all content related to a user session.


Overview

Finding ID Version Rule ID IA Controls Severity
V-32366 SRG-APP-000093-DB-000052 SV-42703r1_rule Medium
Description
While a great deal of effort is made to secure applications to prevent unauthorized access, in certain instances there can be valid requirements to capture, record, and log all content related to a particular user's application session. These instances are reserved for monitoring or investigative purposes supported through policy and are officially sanctioned. Session auditing activities are developed, integrated, and used in consultation with legal counsel in accordance with applicable federal laws, Executive Orders, directives, policies, or regulations. These monitoring events occur at the application layer and as such, may be required to be conducted at a host system however in some cases network monitoring may be involved, as well. Applications must support valid monitoring requirement capabilities performed in accordance with applicable federal laws, Executive Orders, directives, policies, or regulations. This includes the capability to capture, record, and log all content related to an established user session.
STIG Date
Database Security Requirements Guide 2012-07-02

Details

Check Text ( C-40808r1_chk )
Verify, using vendor documentation if required, the DBMS is capable of capturing, recording, and logging all content related to an established user session. If the DBMS is not capable of these actions, this is a finding.
Fix Text (F-36281r1_fix)
Utilize a DBMS capable of capturing, recording, and logging all content related to an established user session, or acquire a third party application to perform this function.