Check: SRG-APP-000343-AS-000030
Application Server SRG:
SRG-APP-000343-AS-000030
(in versions v3 r4 through v2 r2)
Title
The application server must provide access logging that ensures users who are granted a privileged role (or roles) have their privileged activity logged. (Cat II impact)
Discussion
In order to be able to provide a forensic history of activity, the application server must ensure users who are granted a privileged role or those who utilize a separate distinct account when accessing privileged functions or data have their actions logged. If privileged activity is not logged, no forensic logs can be used to establish accountability for privileged actions that occur on the system.
Check Content
Review application server documentation and log configuration to verify the application server logs privileged activity. If the application server is not configured to log privileged activity, this is a finding.
Fix Text
Configure the application server to log privileged activity.
Additional Identifiers
Rule ID: SV-204785r879720_rule
Vulnerability ID: V-204785
Group Title: SRG-APP-000343
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002234 |
The information system audits the execution of privileged functions. |
Controls
Number | Title |
---|---|
AC-6 (9) |
Auditing Use Of Privileged Functions |