STIGQter STIGQter: STIG Summary: MarkLogic Server v9 Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 24 Oct 2024:

MarkLogic Server must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.

DISA Rule

SV-220417r961860_rule

Vulnerability Number

V-220417

Group Title

SRG-APP-000515-DB-000318

Rule Version

ML09-00-012300

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the system to offload MarkLogic audit records.

Add the MarkLogic Server instance under the monitoring of a third-party audit management tool.

Check Contents

Review the system documentation to determine how audit records are offloaded.

If the MarkLogic Server instance is not monitored by a third-party audit management tool, this is a finding.

Vulnerability Number

V-220417

Documentable

False

Rule Version

ML09-00-012300

Severity Override Guidance

Review the system documentation to determine how audit records are offloaded.

If the MarkLogic Server instance is not monitored by a third-party audit management tool, this is a finding.

Check Content Reference

M

Target Key

4064