STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Redis Enterprise DBMS must generate audit records for DoD-defined auditable events within all DBMS/database components.

DISA Rule

SV-251426r960879_rule

Vulnerability Number

V-251426

Group Title

SRG-APP-000089-DB-000064

Rule Version

RD6X-00-012600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This requirement is a permanent finding and cannot be fixed.

This audit requirement must be continuously monitored.

It must be marked as an "open" finding to serve as a reminder to the AO and other stakeholders that this is an approved risk and needs to be reviewed periodically.

Check Contents

This requirement is a permanent finding and cannot be fixed. Redis Enterprise does not currently support session or transactional auditing on the database.

Redis Enterprise does not generate all the DoD-required audit records; therefore this is a finding.

The site must seek AO or ISSO approval for use of Redis Enterprise 6.x with the understanding that not all of the DoD audit requirements are being met.

Vulnerability Number

V-251426

Documentable

False

Rule Version

RD6X-00-012600

Severity Override Guidance

This requirement is a permanent finding and cannot be fixed. Redis Enterprise does not currently support session or transactional auditing on the database.

Redis Enterprise does not generate all the DoD-required audit records; therefore this is a finding.

The site must seek AO or ISSO approval for use of Redis Enterprise 6.x with the understanding that not all of the DoD audit requirements are being met.

Check Content Reference

M

Target Key

5443