STIGQter STIGQter: STIG Summary: Database Security Requirements Guide Version: 3 Release: 1 Benchmark Date: 22 Jan 2021:

The DBMS must generate audit records showing starting and ending time for user access to the database(s).

DISA Rule

SV-206634r617447_rule

Vulnerability Number

V-206634

Group Title

SRG-APP-000505

Rule Version

SRG-APP-000505-DB-000352

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure DBMS audit settings to generate an audit record each time a user (or other principal) logs off or disconnects, whether voluntarily or forced by the system, or because of connection or other failure, from the DBMS.

Ensure that the audit record contains the time of the event, the user ID, and session identifier.

Check Contents

Review the DBMS audit settings. If an audit record is not generated each time a user (or other principal) logs off or disconnects from the DBMS voluntarily, or forced by the system, or because of connection or other failure, this is a finding.

Vulnerability Number

V-206634

Documentable

False

Rule Version

SRG-APP-000505-DB-000352

Severity Override Guidance

Review the DBMS audit settings. If an audit record is not generated each time a user (or other principal) logs off or disconnects from the DBMS voluntarily, or forced by the system, or because of connection or other failure, this is a finding.

Check Content Reference

M

Target Key

2902

Comments