Check: SRG-NET-000077-SDN-000135
SDN Controller SRG:
SRG-NET-000077-SDN-000135
(in versions v2 r1 through v1 r2)
Title
The SDN controller must be configured to produce audit records containing information to establish the source of the events. (Cat II impact)
Discussion
Without establishing the source of the event, it is impossible to establish, correlate, and investigate the events leading up to an outage or attack. In order to compile an accurate risk assessment and provide forensic analysis, security personnel need to know the source (i.e. service, function, node name, IP address, etc.) of the event.
Check Content
Review the SDN controller configuration to determine if the audit records will note the source (e.g., flow, API, IP address, etc.) the event that is being logged. If the SDN controller is not configured to produce audit records containing information to establish the source (e.g., flow, API, IP address, etc.) of the events, this is a finding.
Fix Text
Configure the SDN controller to include the source (e.g., flow, API, IP address, etc.) of the event in the log records.
Additional Identifiers
Rule ID: SV-206720r382864_rule
Vulnerability ID: V-206720
Group Title: SRG-NET-000077
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000133 |
Ensure that audit records containing information that establishes the source of the event. |
Controls
Number | Title |
---|---|
AU-3 |
Content of Audit Records |