STIGQter STIGQter: STIG Summary: Symantec ProxySG NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2020:

Symantec ProxySG must back up event logs onto a different system or system component than the system or component being audited.

DISA Rule

SV-104509r1_rule

Vulnerability Number

V-94679

Group Title

SRG-APP-000125-NDM-000241

Rule Version

SYMP-NM-000140

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure event logging to a remote events server to ensure that event logs are recorded on a different system.

To configure Syslog:
1. Log on to the Web Management Console.
2. Click Maintenance >> Event Logging >> Syslog.
3. Enter the IP address or name of a syslog server, click "OK".
4. Repeat step 3 for any additional syslog servers.
5. Click "Apply".

Check Contents

Verify event logging to a remote events collection server is configured in order to send event logs to a different system.

1. Log on to the Web Management Console.
2. Click Maintenance >> Event Logging >> Syslog.
3. Confirm that "Syslog" is "Enabled" and a syslog server is specified.

If Symantec ProxySG does not back up event logs onto a different system or system component than the system or component being audited, this is a finding.

Vulnerability Number

V-94679

Documentable

False

Rule Version

SYMP-NM-000140

Severity Override Guidance

Verify event logging to a remote events collection server is configured in order to send event logs to a different system.

1. Log on to the Web Management Console.
2. Click Maintenance >> Event Logging >> Syslog.
3. Confirm that "Syslog" is "Enabled" and a syslog server is specified.

If Symantec ProxySG does not back up event logs onto a different system or system component than the system or component being audited, this is a finding.

Check Content Reference

M

Target Key

3517

Comments