Check: DSN15.02
Defense Switched Network (DSN) STIG:
DSN15.02
(in versions v2 r8 through v2 r7)
Title
Audit records do not record the identity of each person and terminal device having access to switch software or databases. (Cat II impact)
Discussion
Requirement: The IAO will ensure that the auditing process records the identity of each person and terminal device having access to switch software or databases The identity of the individual user and the terminal used during their session will be recorded in the audit records. This is needed for accountability of command issues and actions taken during each session.
Check Content
Have the IAO or SA demonstrate compliance with the requirement; minimally on a sampling of the related or effected devices. Inspect configuration files as applicable.
Fix Text
Ensure audit records contain the user and terminal identity.
Additional Identifiers
Rule ID: SV-8460r1_rule
Vulnerability ID: V-7974
Group Title: Audit records do not record individual identity
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |