Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-228993 | F5BI-DM-000151 | SV-228993r557520_rule | Medium |
Description |
---|
Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state. Additionally, sensitive account information must not be revealed through error messages to unauthorized personnel or their designated representatives. |
STIG | Date |
---|---|
F5 BIG-IP Device Management 11.x Security Technical Implementation Guide | 2020-09-28 |
Check Text ( C-31308r518024_chk ) |
---|
Verify the BIG-IP appliance is configured to reveal error messages only to authorized individuals (ISSO, ISSM, and SA). Navigate to the BIG-IP System manager >> Logs >> Configuration >> Options. Verify that "Log Access" is granted only to authorized individuals (ISSO, ISSM, and SA). If the BIG-IP appliance reveals error messages to any unauthorized individuals (ISSO, ISSM, and SA), this is a finding. |
Fix Text (F-31285r518025_fix) |
---|
Configure the BIG-IP appliance to reveal error messages only to authorized individuals (ISSO, ISSM, and SA). |