Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000080-NDM-000054 | SRG-NET-000080-NDM-000054 | SRG-NET-000080-NDM-000054_rule | Low |
Description |
---|
Audit record content that may be necessary to satisfy this requirement includes timestamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, file names involved, and access control or flow control ACLs or policy filters invoked. This capability is critical for accurate forensic analysis. |
STIG | Date |
---|---|
Network Device Management Security Requirements Guide | 2013-07-30 |
Check Text ( C-SRG-NET-000080-NDM-000054_chk ) |
---|
If the organization does not require organizationally defined additional information to be captured in the audit log from the network device, this is not a finding. Examine the audit log configuration on the network device or view several alert records on the organization's central audit log server. Verify the entries sent to the audit log include organizationally defined additional information. If the audit log event records do not include organizationally defined additional information, this is a finding. |
Fix Text (F-SRG-NET-000080-NDM-000054_fix) |
---|
Configure the network device to ensure entries sent to the audit log include organizationally defined additional information. Organizational requirements for what audit events are required may be defined by type, location, or subject. |