SV-250350r961812_rule
V-250350
SRG-APP-000499-AS-000224
IBMW-LS-001190
CAT II
10
Modify the ${server.config.dir}/server.xml file and configure the audit-1.0 feature.
<featureManager>
<feature>audit-1.0</feature>
</featureManager>
Configure the auditFileHandler setting to record SECURITY_AUTHN and SECURITY_AUTHZ events.
<auditFileHandler>
<events name="AllAuthn" eventName="SECURITY_AUTHN"/>
<events name="AllAuthz" eventName="SECURITY_AUTHZ" />
</auditFileHandler>
Review audit logs located under the ${server.config.dir}/logs directory and ensure AUTHN and AUTHZ events are logged.
Review the ${server.config.dir}/server.xml file, verify the audit-1.0 feature is enabled. Also verify the auditFile Handler is configured to log AUTHN and AUTHZ events.
If the audit1.0 feature is not enabled, this is a finding.
If the SECURITY_AUTHN and SECURITY_AUTHZ event handlers are not configured, this is a finding.
<featureManager>
<feature>audit-1.0</feature>
</featureManager>
<auditFileHandler>
<events name="AllAuthn" eventName="SECURITY_AUTHN" />
<events name="AllAuthz" eventName="SECURITY_AUTHZ" />
</auditFileHandler>
V-250350
False
IBMW-LS-001190
Review the ${server.config.dir}/server.xml file, verify the audit-1.0 feature is enabled. Also verify the auditFile Handler is configured to log AUTHN and AUTHZ events.
If the audit1.0 feature is not enabled, this is a finding.
If the SECURITY_AUTHN and SECURITY_AUTHZ event handlers are not configured, this is a finding.
<featureManager>
<feature>audit-1.0</feature>
</featureManager>
<auditFileHandler>
<events name="AllAuthn" eventName="SECURITY_AUTHN" />
<events name="AllAuthz" eventName="SECURITY_AUTHZ" />
</auditFileHandler>
M
5424