UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The application must be configured to reveal error messages only to authorized individuals (ISSO, ISSM, and SA).


Overview

Finding ID Version Rule ID IA Controls Severity
V-228993 F5BI-DM-000151 SV-228993r557520_rule Medium
Description
Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state. Additionally, sensitive account information must not be revealed through error messages to unauthorized personnel or their designated representatives.
STIG Date
F5 BIG-IP Device Management 11.x Security Technical Implementation Guide 2020-09-28

Details

Check Text ( C-31308r518024_chk )
Verify the BIG-IP appliance is configured to reveal error messages only to authorized individuals (ISSO, ISSM, and SA).

Navigate to the BIG-IP System manager >> Logs >> Configuration >> Options.

Verify that "Log Access" is granted only to authorized individuals (ISSO, ISSM, and SA).

If the BIG-IP appliance reveals error messages to any unauthorized individuals (ISSO, ISSM, and SA), this is a finding.
Fix Text (F-31285r518025_fix)
Configure the BIG-IP appliance to reveal error messages only to authorized individuals (ISSO, ISSM, and SA).