Check: EPAS-00-011800
EnterpriseDB Postgres Advanced Server (EPAS) STIG:
EPAS-00-011800
(in version v1 r1)
Title
The EDB Postgres Advanced Server must generate audit records when successful logons or connections occur. (Cat II impact)
Discussion
For completeness of forensic analysis, it is necessary to track who/what (a user or other principal) logs on to the DBMS.
Check Content
Execute the following SQL as the "enterprisedb" operating system user: > psql edb -c "SHOW edb_audit_connect" If the result is not "all" or if the current setting for this requirement has not been noted and approved by the organization in the system documentation, this is a finding.
Fix Text
Execute the following SQL as the "enterprisedb" operating system user: > psql edb -c "ALTER SYSTEM SET edb_audit_connect = 'all'" > psql edb -c "ALTER SYSTEM SET edb_audit_disconnect = 'all'" >psql edb -c "SELECT pg_reload_conf()" or Update the system documentation to note the organizationally approved setting and corresponding justification of the setting for this requirement.
Additional Identifiers
Rule ID: SV-259316r939001_rule
Vulnerability ID: V-259316
Group Title: SRG-APP-000503-DB-000350
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000172 |
The information system generates audit records for the events defined in AU-2 d. with the content defined in AU-3. |
Controls
Number | Title |
---|---|
AU-12 |
Audit Generation |