SV-220343r960879_rule
V-220343
SRG-APP-000089-DB-000064
ML09-00-000500
CAT II
10
Configure MarkLogic to generate audit records for at least the DoD minimum or organization-defined set of events.
Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. Click the Auditing icon on the left tree menu.
4. Set the audit enabled field to true.
5. Configure the auditable events to meet DoD minimum requirements.
Check DBMS auditing to determine whether organization-defined auditable events are being audited by the system.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. Click the Auditing icon on the left tree menu.
4. Inspect the audit enabled field. A value of false means there is no auditing and this is a finding.
5. If audit enabled field is true, but the selected auditable events do not meet DoD minimum requirements, this is a finding.
V-220343
False
ML09-00-000500
Check DBMS auditing to determine whether organization-defined auditable events are being audited by the system.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. Click the Auditing icon on the left tree menu.
4. Inspect the audit enabled field. A value of false means there is no auditing and this is a finding.
5. If audit enabled field is true, but the selected auditable events do not meet DoD minimum requirements, this is a finding.
M
4064