Check: SRG-APP-000503-DB-000350
Database SRG:
SRG-APP-000503-DB-000350
(in versions v4 r3 through v2 r9)
Title
The DBMS must generate audit records when successful logons or connections occur. (Cat II impact)
Discussion
For completeness of forensic analysis, it is necessary to track who/what (a user or other principal) logs on to the DBMS.
Check Content
Review the DBMS audit settings. If an audit record is not generated each time a user (or other principal) logs on or connects to the DBMS, this is a finding.
Fix Text
Configure DBMS audit settings to generate an audit record each time a user (or other principal) logs on or connects to the DBMS. Ensure that the audit record contains the time of the event, the user ID, and session identifier.
Additional Identifiers
Rule ID: SV-206630r961824_rule
Vulnerability ID: V-206630
Group Title: SRG-APP-000503
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000172 |
Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3. |
Controls
Number | Title |
---|---|
AU-12 |
Audit Generation |