SV-220348r960915_rule
V-220348
SRG-APP-000109-DB-000049
ML09-00-001600
CAT II
10
Configure the database to go offline, rolling back all in-flight transactions, in the case of an auditing failure due to insufficient disk space.
Perform the fix from the MarkLogic Admin Interface with a user that holds administrative-level privileges:
1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. On the Configuration tab set the value of "failover enabled" to "false".
4. Click OK to save the configuration.
If the application owner has determined the need for system availability outweighs the need for a complete audit trail, this is not applicable.
If the system is configured for High Availability (HA), and the application owner has determined the need for a complete audit trail outweighs the need for system availability, this is a finding.
The following are the minimum configuration requirements for HA:
- Failover enabled = True for the Group
- Security database forests are configured with replica forests
- Databases associated with the users application are configured with replica forests
If HA is a requirement for Administrative functions:
- App Services database forests are configured with replica forests
- Modules database forests are configured with replica forests
- Documents database forests are configured with replica forests
- Triggers database forests are configured with replica forests
Perform the check for HA from the MarkLogic Admin Interface with a user that holds administrative-level privileges:
1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. On the Configuration tab, check the value of "failover enabled".
True = HA can be enabled
False = HA cannot be enabled
4. Click the Databases icon in the left tree menu.
5. Click the Security Database.
6. Click the Status Tab.
7. Review the Forest section:
a. Count the number of forests with a state of "open".
b. Count the number of forests with a state of "[sync|async|wait] replicating".
c. The number of replicating forests should be greater than or equal to the number of open forests.
8. Repeat steps 4-7 for the user application databases (data/content, modules, triggers, etc.).
9. Repeat steps 4-7 for the following databases if HA is required for Administrative functions:
- App Services
- Modules
- Documents
- Triggers
V-220348
False
ML09-00-001600
If the application owner has determined the need for system availability outweighs the need for a complete audit trail, this is not applicable.
If the system is configured for High Availability (HA), and the application owner has determined the need for a complete audit trail outweighs the need for system availability, this is a finding.
The following are the minimum configuration requirements for HA:
- Failover enabled = True for the Group
- Security database forests are configured with replica forests
- Databases associated with the users application are configured with replica forests
If HA is a requirement for Administrative functions:
- App Services database forests are configured with replica forests
- Modules database forests are configured with replica forests
- Documents database forests are configured with replica forests
- Triggers database forests are configured with replica forests
Perform the check for HA from the MarkLogic Admin Interface with a user that holds administrative-level privileges:
1. Click the Groups icon.
2. Click the group in which the configuration to check resides (e.g., Default).
3. On the Configuration tab, check the value of "failover enabled".
True = HA can be enabled
False = HA cannot be enabled
4. Click the Databases icon in the left tree menu.
5. Click the Security Database.
6. Click the Status Tab.
7. Review the Forest section:
a. Count the number of forests with a state of "open".
b. Count the number of forests with a state of "[sync|async|wait] replicating".
c. The number of replicating forests should be greater than or equal to the number of open forests.
8. Repeat steps 4-7 for the user application databases (data/content, modules, triggers, etc.).
9. Repeat steps 4-7 for the following databases if HA is required for Administrative functions:
- App Services
- Modules
- Documents
- Triggers
M
4064