Check: NET-SDN-016
SDN Using NV STIG:
NET-SDN-016
(in version v1 r1)
Title
Servers hosting SDN controllers must have logging enabled. (Cat II impact)
Discussion
It is critical for both network and security personnel to be aware of the state of the SDN infrastructure to maintain network stability. Associating logged events that have occurred within the SDN controller as well as network state information provided by the SDN-enabled components is essential to compile an accurate risk assessment and troubleshoot network outages.
Check Content
Review all servers hosting an SDN controller and verify that logging has been enabled. If logging is not enabled on all servers hosting an SDN controller, this is a finding.
Fix Text
Enable logging on all servers hosting an SDN controller.
Additional Identifiers
Rule ID: SV-87755r1_rule
Vulnerability ID: V-73103
Group Title: NET-SDN-016
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001846 |
The organization defines information system components that will generate the audit records which are to be captured for centralized management of the content. |
Controls
Number | Title |
---|---|
AU-3(2) |
Centralized Management of Planned Audit Record Content |