Check: NET0395
Network - Firewall:
NET0395
(in versions v8 r25 through v8 r21)
Title
The ISSO must ensure the alarm message identifying the potential security violation makes accessible the audit record contents associated with the event(s). (Cat III impact)
Discussion
The relevant audit information must be available to administrators. The firewall shall immediately display an alarm message, identifying the potential security violation and make accessible the audit record contents associated with the event(s) that generated the alarm.
Check Content
Review the firewall configuration to determine what alerts have been defined and how the notifications are performed. The relevant audit information must be available to administrators. The message will not be scrolled off the screen due to other activities taking place (e.g., the Audit Administrator is running an audit report). If the device does not write violations to the console and make accessible the audit record contents, this is a finding.
Fix Text
Configure the firewall to write violations to the console and make accessible the audit record contents.
Additional Identifiers
Rule ID:
Vulnerability ID: V-14653
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |