Check: ML09-00-011700
MarkLogic Server v9 STIG:
ML09-00-011700
(in versions v2 r2 through v1 r1)
Title
MarkLogic must be able to generate audit records when successful accesses to objects occur. (Cat II impact)
Discussion
Without tracking all or selected types of access to all or selected objects (tables, views, procedures, functions, etc.), it would be difficult to establish, correlate, and investigate the events relating to an incident, or identify those responsible for one.
Check Content
Review audit settings to verify objects identified by the application owner, for which access must be audited, are being audited. Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges. 1. Click the Groups icon. 2. Click the group in which the configuration to be checked resides (e.g., Default). 3. Click the Auditing icon on the left tree menu. 4. Inspect the audit enabled field. A value of false means auditing is not enabled and this is a finding. 5. If any audit events identified in the System Security Plan are not enabled, this is a finding. 6. If the Audit Restrictions - Outcome is not Both, this is a finding. 7. If any Audit Restriction Inclusions/Exclusions are not documented in the System Security Plan, this is a finding.
Fix Text
Configure audit settings to create audit records when the specified access to the specified objects occurs. Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges. 1. Click the Groups icon. 2. Click the group in which the configuration to check resides (e.g., Default). 3. Click the Auditing icon on the left tree menu. 4. Set the audit enabled field to true. 5. Enable any audit events identified as required in the System Security Plan (SSP). 6. Set the Audit Restrictions - Outcome to Both. 7. If any Audit Restriction - Inclusions/Exclusions are approved in the SSP, ensure they have been applied.
Additional Identifiers
Rule ID: SV-220413r879878_rule
Vulnerability ID: V-220413
Group Title: SRG-APP-000507-DB-000356
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000172 |
The information system generates audit records for the events defined in AU-2 d. with the content defined in AU-3. |
Controls
Number | Title |
---|---|
AU-12 |
Audit Generation |