STIGQter STIGQter: STIG Summary: PostgreSQL 9.x Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Oct 2020:

PostgreSQL must provide audit record generation capability for DoD-defined auditable events within all DBMS/database components.

DISA Rule

SV-214114r508027_rule

Vulnerability Number

V-214114

Group Title

SRG-APP-000089-DB-000064

Rule Version

PGS9-00-007400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure PostgreSQL to generate audit records for at least the DoD minimum set of events.

Using pgaudit PostgreSQL can be configured to audit these requests. See supplementary content APPENDIX-B for documentation on installing pgaudit.

To ensure that logging is enabled, review supplementary content APPENDIX-C for instructions on enabling logging.

Check Contents

Check PostgreSQL auditing to determine whether organization-defined auditable events are being audited by the system.

If organization-defined auditable events are not being audited, this is a finding.

Vulnerability Number

V-214114

Documentable

False

Rule Version

PGS9-00-007400

Severity Override Guidance

Check PostgreSQL auditing to determine whether organization-defined auditable events are being audited by the system.

If organization-defined auditable events are not being audited, this is a finding.

Check Content Reference

M

Target Key

3994

Comments