Automation Controller must use external log providers that can collect user activity logs in independent, protected repositories to prevent modification or repudiation.
DISA Rule
SV-256900r960864_rule
Vulnerability Number
V-256900
Group Title
SRG-APP-000080-AS-000045
Rule Version
APAS-AT-000017
Severity
CAT II
CCI(s)
- CCI-000139 - Alert organization-defined personnel or roles within an organization-defined time period in the event of an audit logging process failure.
- CCI-000166 - Provide irrefutable evidence that an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-000174 - Compile audit records from organization-defined information system components into a system-wide (logical or physical) audit trail that is time-correlated to within an organization-defined level of tolerance for relationship between time stamps of individual records in the audit trail.
- CCI-001348 - Store audit records on an organization-defined frequency in a repository that is part of a physically different system or system component that the system or component being audited.
- CCI-001851 - Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging.
- CCI-001876 - Provide an audit reduction capability that supports on-demand reporting requirements.
Weight
10
Fix Recommendation
Log in to Automation Controller as an administrator.
Navigate to Settings >> System >> Logging setting.
Click "Edit" and set the following fields:
Enable External Logging = On
Logging Aggregator Level Threshold = DEBUG
TCP Connection Timeout = 5 (default) or the organizational timeout
Enable/disable HTTPS certificate verification = On
Logging Aggregator <> (Default) "Not configured"
Click "Save".
Check Contents
Log in to Automation Controller as an administrator.
Navigate to Settings >> System >> Logging setting.
The following parameters must be set:
Enable External Logging = On
Logging Aggregator Level Threshold = DEBUG
TCP Connection Timeout = 5 (default) or the organizational timeout
Enable/disable HTTPS certificate verification = On
Logging Aggregator <> (Default) "Not configured"
If any of these settings are incorrect, this is a finding.
Vulnerability Number
V-256900
Documentable
False
Rule Version
APAS-AT-000017
Severity Override Guidance
Log in to Automation Controller as an administrator.
Navigate to Settings >> System >> Logging setting.
The following parameters must be set:
Enable External Logging = On
Logging Aggregator Level Threshold = DEBUG
TCP Connection Timeout = 5 (default) or the organizational timeout
Enable/disable HTTPS certificate verification = On
Logging Aggregator <> (Default) "Not configured"
If any of these settings are incorrect, this is a finding.
Check Content Reference
M
Target Key
5534