Check: WSDP-NM-000128
IBM DataPower Network Device Management STIG:
WSDP-NM-000128
(in versions v1 r2 through v1 r1)
Title
The DataPower Gateway must off-load audit records onto a different system or media than the system being audited. (Cat II impact)
Discussion
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity.
Check Content
Go to Administration-Miscellaneous >> Manage Log Targets, Event Subscription Tab and check for acceptable configuration in the name and category fields. Go to the Main tab and check for the desired values in the protocol field. If no Log Targets are configured, this is a finding.
Fix Text
Use the CLI copy command. Syntax: copy -f sourceURL destinationURL -f is an optional switch that forces an unconditional copy. Example: xi52(config)# copy audit:audit-log sftp://test@xx.xx.x.xxx/LOGS/x/Week1.log. Or, go to Administration-Miscellaneous >> Manage Log Targets, Event Subscription Tab, provide a name, press Add, choose Category “audit”. Go to Main tab, choose protocol (NFS, SMTP, SNMP, File, etc.) and configure.
Additional Identifiers
Rule ID: SV-79661r1_rule
Vulnerability ID: V-65171
Group Title: SRG-APP-000515-NDM-000325
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001851 |
The information system off-loads audit records per organization-defined frequency onto a different system or media than the system being audited. |
Controls
Number | Title |
---|---|
AU-4 (1) |
Transfer To Alternate Storage |