The TippingPoint SMS must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).
DISA Rule
SV-242259r1028385_rule
Vulnerability Number
V-242259
Group Title
SRG-APP-000026-NDM-000208
Rule Version
TIPP-NM-000670
Severity
CAT I
CCI(s)
- CCI-000366 - Implement the security configuration settings.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
- CCI-000018 - Automatically audit account creation actions.
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-003938 - Automatically generate audit records of the enforcement actions.
- CCI-001851 - Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging.
- CCI-002234 - Log the execution of privileged functions.
- CCI-002605 - Install security-relevant software updates within an organization-defined time period of the release of the updates.
- CCI-002130 - Automatically audit account enabling actions.
- CCI-003831 - Alert organization-defined personnel or roles upon detection of unauthorized access, modification, or deletion of audit information.
Weight
10
Fix Recommendation
1. Navigate to Admin >> Server properties >> Syslog >> New.
2. Click "enable".
3. Click "TCP" or "Encrypted TCP".
4. Under Log Type, select "Device Audit".
5. Facility is "Log Audit".
6. Timestamp: SMS Current Time.
7. Check "Include SMS hostname in Header".
8. Click "OK".
9. Repeat these steps for the following three other Log Types: Device System, SMS Audit, and SMS System.
10. Repeat steps to configure a second Syslog server IP host information.
Note: Syslog servers used must be configured to alert system administrator and ISSO upon detection of unauthorized access, modification, or deletion of audit information.
Check Contents
1. Navigate to Admin >> Server properties >> Syslog.
2. Verify the configuration enables TCP or Encrypted TCP.
3. Verify Device Audit, Device System, SMS Audit, and SMS System log types are enabled and configured.
If syslog is not configured to use TCP or Encrypted TCP or does not include the four log types, this is a finding.
Vulnerability Number
V-242259
Documentable
False
Rule Version
TIPP-NM-000670
Severity Override Guidance
1. Navigate to Admin >> Server properties >> Syslog.
2. Verify the configuration enables TCP or Encrypted TCP.
3. Verify Device Audit, Device System, SMS Audit, and SMS System log types are enabled and configured.
If syslog is not configured to use TCP or Encrypted TCP or does not include the four log types, this is a finding.
Check Content Reference
M
Target Key
5369