STIGQter STIGQter: STIG Summary: NetApp ONTAP DSC 9.x Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

ONTAP must automatically audit account-enabling actions.

DISA Rule

SV-246925r961290_rule

Vulnerability Number

V-246925

Group Title

SRG-APP-000319-NDM-000283

Rule Version

NAOT-AC-000004

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Use "cluster log-forwarding show" to identify defined ONTAP remote syslog servers. If no remote syslog servers are defined, use "cluster log-forwarding create" to define a syslog destination.

On the remote syslog server, use commands available to check for new account creation or enabling a disabled account.

Check Contents

Use "cluster log-forwarding show" to see if a remote syslog destination is defined for ONTAP.

Use commands available on the remote syslog server to check for new account creation or enabling a disabled account.

If ONTAP does not automatically audit account-enabling actions, this is a finding.

Vulnerability Number

V-246925

Documentable

False

Rule Version

NAOT-AC-000004

Severity Override Guidance

Use "cluster log-forwarding show" to see if a remote syslog destination is defined for ONTAP.

Use commands available on the remote syslog server to check for new account creation or enabling a disabled account.

If ONTAP does not automatically audit account-enabling actions, this is a finding.

Check Content Reference

M

Target Key

5415