Check: SRG-APP-000093-MAPP-NA
Mobile Application SRG:
SRG-APP-000093-MAPP-NA
(in version v1 r1)
Title
The application must provide the capability to capture, record, and log all content related to a user session. (Cat II impact)
Discussion
While a great deal of effort is made to secure applications so as to prevent unauthorized access, in certain instances there can be valid requirements to capture, record and log all content related to a particular user's application session. These instances are reserved for monitoring or investigative purposes supported through policy and are officially sanctioned. Session auditing activities are developed, integrated, and used in consultation with legal counsel in accordance with applicable federal laws, Executive Orders, directives, policies, or regulations. These monitoring events occur at the application layer and as such maybe required to be conducted at a host system however in some cases network monitoring may be involved as well. Applications must support valid monitoring requirement capabilities performed in accordance with applicable federal laws, Executive Orders, directives, policies, or regulations. This includes the capability to capture, record and log all content related to an established user session. Rationale for non-applicability: The MOS SRG contains a requirement for logging application startup and a number of other security critical events. No further audit logging must be coded into each application running on the MOS, but application developers may do so for application-specific concerns.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46571r1_rule
Vulnerability ID: V-35284
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001462 |
The information system provides the capability for authorized users to capture/record and log content related to a user session. |
Controls
Number | Title |
---|---|
AU-14(2) |
Capture/record and Log Content |