STIGQter STIGQter: STIG Summary: Application Server Security Requirements Guide Version: 3 Release: 1 Benchmark Date: 23 Oct 2020:

The application must generate log records showing starting and ending times for user access to the application server management interface.

DISA Rule

SV-204828r508029_rule

Vulnerability Number

V-204828

Group Title

SRG-APP-000505

Rule Version

SRG-APP-000505-AS-000230

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the application server to generate log records showing starting and ending times of user access to the management interface.

Check Contents

Review the application server documentation and the system configuration to determine if the application server generates log records showing starting and ending times for user access to the management interface.

If log records are not generated showing starting and ending times of user access to the management interface, this is a finding.

Vulnerability Number

V-204828

Documentable

False

Rule Version

SRG-APP-000505-AS-000230

Severity Override Guidance

Review the application server documentation and the system configuration to determine if the application server generates log records showing starting and ending times for user access to the management interface.

If log records are not generated showing starting and ending times of user access to the management interface, this is a finding.

Check Content Reference

M

Target Key

2900

Comments