SV-220342r960864_rule
V-220342
SRG-APP-000080-DB-000063
ML09-00-000400
CAT II
10
Configure MarkLogic audit logs to ensure auditing includes details identifying the individual user.
Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. Click the Auditing icon on the left tree menu.
4. Set the audit enabled field to true.
5. Configure the settings to meet DoD minimum requirements for protection against a user falsely repudiating.
Review the configuration of audit logs to determine whether auditing includes details identifying the individual user. If it does not, this is a finding.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. Click the Auditing icon on the left tree menu.
4. Inspect the audit-enabled field. A value of false means there is no auditing identifying the individual user and this is a finding.
5. If audit enabled field is true, but the settings do not meet the DoD minimum requirements for non-repudiation, this is a finding.
V-220342
False
ML09-00-000400
Review the configuration of audit logs to determine whether auditing includes details identifying the individual user. If it does not, this is a finding.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. Click the Auditing icon on the left tree menu.
4. Inspect the audit-enabled field. A value of false means there is no auditing identifying the individual user and this is a finding.
5. If audit enabled field is true, but the settings do not meet the DoD minimum requirements for non-repudiation, this is a finding.
M
4064