The ICS must be configured to audit the execution of privileged functions such as accounts additions and changes.
DISA Rule
SV-258601r997507_rule
Vulnerability Number
V-258601
Group Title
SRG-APP-000343-NDM-000289
Rule Version
IVCS-NM-000060
Severity
CAT II
CCI(s)
- CCI-000018 - Automatically audit account creation actions.
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-000382 - Configure the system to prohibit or restrict the use of organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services.
- CCI-000803 - Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
- CCI-001188 - Generate a unique session identifier for each session with organization-defined randomness requirements.
- CCI-001368 - Enforce approved authorizations for controlling the flow of information within the system based on organization-defined information flow control policies.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001405 - Automatically audit account removal actions.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
- CCI-003938 - Automatically generate audit records of the enforcement actions.
- CCI-001941 - Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts.
- CCI-002130 - Automatically audit account enabling actions.
- CCI-002234 - Log the execution of privileged functions.
- CCI-002385 - Protect against or limit the effects of organization-defined types of denial of service events.
- CCI-002890 - Implement organization-defined cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.
- CCI-003123 - Implement organization-defined cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
Weight
10
Fix Recommendation
Enable logging for admin event actions.
In the ICS Web UI, navigate to System >> Log/Monitoring >> Admin Access >> Settings.
1. Check the box for Administrator changes under the section "Select Events to Log".
2. Click "Save Changes".
Check Contents
In the ICS Web UI, navigate to System >> Log/Monitoring >> Admin Access >> Settings, under the section "Select Events to Log".
If Administrator changes is enabled for events logging, this is a finding.
Vulnerability Number
V-258601
Documentable
False
Rule Version
IVCS-NM-000060
Severity Override Guidance
In the ICS Web UI, navigate to System >> Log/Monitoring >> Admin Access >> Settings, under the section "Select Events to Log".
If Administrator changes is enabled for events logging, this is a finding.
Check Content Reference
M
Target Key
5558