STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must protect against a user falsely repudiating having performed organization-defined actions.

DISA Rule

SV-220342r960864_rule

Vulnerability Number

V-220342

Group Title

SRG-APP-000080-DB-000063

Rule Version

ML09-00-000400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure MarkLogic audit logs to ensure auditing includes details identifying the individual user.

Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. Click the Auditing icon on the left tree menu.
4. Set the audit enabled field to true.
5. Configure the settings to meet DoD minimum requirements for protection against a user falsely repudiating.

Check Contents

Review the configuration of audit logs to determine whether auditing includes details identifying the individual user. If it does not, this is a finding.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. Click the Auditing icon on the left tree menu.
4. Inspect the audit-enabled field. A value of false means there is no auditing identifying the individual user and this is a finding.
5. If audit enabled field is true, but the settings do not meet the DoD minimum requirements for non-repudiation, this is a finding.

Vulnerability Number

V-220342

Documentable

False

Rule Version

ML09-00-000400

Severity Override Guidance

Review the configuration of audit logs to determine whether auditing includes details identifying the individual user. If it does not, this is a finding.

Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.

1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. Click the Auditing icon on the left tree menu.
4. Inspect the audit-enabled field. A value of false means there is no auditing identifying the individual user and this is a finding.
5. If audit enabled field is true, but the settings do not meet the DoD minimum requirements for non-repudiation, this is a finding.

Check Content Reference

M

Target Key

4064