Check: SRG-APP-000508-DB-000358
Database SRG:
SRG-APP-000508-DB-000358
(in versions v3 r4 through v2 r10)
Title
The DBMS must generate audit records for all direct access to the database(s). (Cat II impact)
Discussion
In this context, direct access is any query, command, or call to the DBMS that comes from any source other than the application(s) that it supports. Examples would be the command line or a database management utility program. The intent is to capture all activity from administrative and non-standard sources.
Check Content
If the DBMS does not generate audit records for all direct access to the database(s), this is a finding.
Fix Text
Configure the DBMS to generate audit records for all direct access to the database(s).
Additional Identifiers
Rule ID: SV-206638r879879_rule
Vulnerability ID: V-206638
Group Title: SRG-APP-000508
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000172 |
The information system generates audit records for the events defined in AU-2 d. with the content defined in AU-3. |
Controls
Number | Title |
---|---|
AU-12 |
Audit Generation |