Check: WSDP-NM-000085
IBM DataPower Network Device Management STIG:
WSDP-NM-000085
(in versions v1 r2 through v1 r1)
Title
The DataPower Gateway must automatically audit account enabling actions. (Cat II impact)
Discussion
Once an attacker establishes initial access to a system, the attacker often attempts to create a persistent method of reestablishing access. One way to accomplish this is for the attacker to simply enable a new or disabled account. Notification of account enabling is one method for mitigating this risk. A comprehensive account management process will ensure an audit trail which documents the creation of application user accounts and notifies administrators and Information System Security Officers (ISSOs). Such a process greatly reduces the risk that accounts will be surreptitiously created and provides logging that can be used for forensic purposes.
Check Content
View the logging settings: Objects >> Logging Configuration >> Audit Log Settings. Then examine the audit log after enabling or disabling an account (the most recent entry will be at the bottom of the log). If this message is not present, this is a finding.
Fix Text
Configure a comprehensive audit trail by turning on the audit log using the web interface (Objects >> Logging Configuration >> Audit Log Settings) then setting the desired level of logging detail for audit-events.
Additional Identifiers
Rule ID: SV-79617r1_rule
Vulnerability ID: V-65127
Group Title: SRG-APP-000319-NDM-000283
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002130 |
The information system automatically audits account enabling actions. |
Controls
Number | Title |
---|---|
AC-2 (4) |
Automated Audit Actions |