Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-37110 | SRG-NET-000113-FW-000065 | SV-48871r1_rule | Low |
Description |
---|
Auditing and logging are key components of any security architecture. It is essential for security personnel to know what is being done, what attempted to be done, where it was done, when it was done, and by whom in order to compile an accurate risk assessment. Logging the actions of specific events provides a means to investigate an attack, recognize resource utilization or capacity thresholds, or to simply identify an improperly configured firewall. Many events are mandated by other controls; however, organizations must also define additional events for logging based on mission requirements. |
STIG | Date |
---|---|
Firewall Security Requirements Guide | 2013-04-24 |
Check Text ( C-45482r1_chk ) |
---|
Obtain a list of organizationally defined events which should be logged. Search for a sampling of these events in the audit log entries. If the firewall audit log records do not show audit events for the organizationally defined events, this is a finding. |
Fix Text (F-42055r1_fix) |
---|
Create a list of organizationally defined audit events which should be logged. Configure the firewall implementation to log the required events. |