Check: SRG-APP-000503-DB-000350
Database SRG:
SRG-APP-000503-DB-000350
(in versions v3 r4 through v2 r10)
Title
The DBMS must generate audit records when successful logons or connections occur. (Cat II impact)
Discussion
For completeness of forensic analysis, it is necessary to track who/what (a user or other principal) logs on to the DBMS.
Check Content
Review the DBMS audit settings. If an audit record is not generated each time a user (or other principal) logs on or connects to the DBMS, this is a finding.
Fix Text
Configure DBMS audit settings to generate an audit record each time a user (or other principal) logs on or connects to the DBMS. Ensure that the audit record contains the time of the event, the user ID, and session identifier.
Additional Identifiers
Rule ID: SV-206630r879874_rule
Vulnerability ID: V-206630
Group Title: SRG-APP-000503
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000172 |
The information system generates audit records for the events defined in AU-2 d. with the content defined in AU-3. |
Controls
Number | Title |
---|---|
AU-12 |
Audit Generation |