Check: AKSD-DM-000005
Akamai KSD Service Impact Level 2 NDM STIG:
AKSD-DM-000005
(in version v1 r1)
Title
Upon successful login, the Akamai Luna Portal must notify the administrator of the date and time of the last login. (Cat II impact)
Discussion
Administrators need to be aware of activity that occurs regarding their network device management account. Providing administrators with information regarding the date and time of their last successful login allows them to determine if any unauthorized activity has occurred. This incorporates all methods of login, including but not limited to SSH, HTTP, HTTPS, and physical connectivity.
Check Content
Verify that the activity log is showing user login data: 1. Log in to the Luna Portal. 2. Verify that one of the four widgets includes the activity log. If the activity log is not showing, this is a finding.
Fix Text
Configure the activity log to appear in the "My Akamai" section. 1. Select the gear icon on one of the four widgets. 2. Select the activity log in the left column. 3. Check the box for "All Logins".
Additional Identifiers
Rule ID: SV-91153r1_rule
Vulnerability ID: V-76457
Group Title: SRG-APP-000075-NDM-000217
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000052 |
The information system notifies the user, upon successful logon (access) to the system, of the date and time of the last logon (access). |
CCI-000366 |
The organization implements the security configuration settings. |