Check: SRG-APP-000092-NDM-000224
Network Device Management SRG:
SRG-APP-000092-NDM-000224
(in versions v4 r3 through v2 r7)
Title
The network device must initiate session auditing upon startup. (Cat II impact)
Discussion
If auditing is enabled late in the startup process, the actions of some start-up processes may not be audited. Some audit systems also maintain state information only available if auditing is enabled before a given process is created.
Check Content
Determine if the network device initiates session auditing upon startup. This requirement may be verified by validated test results. If the network device does not initiate session auditing upon startup, this is a finding.
Fix Text
Configure the network device to initiate session auditing upon startup.
Additional Identifiers
Rule ID: SV-202029r879562_rule
Vulnerability ID: V-202029
Group Title: SRG-APP-000092
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001464 |
The information system initiates session audits at system start-up. |
Controls
Number | Title |
---|---|
AU-14 (1) |
System Start-Up |