Audit logging must be enabled on MKE.
DISA Rule
SV-260914r966099_rule
Vulnerability Number
V-260914
Group Title
SRG-APP-000092-CTR-000165
Rule Version
CNTR-MK-000220
Severity
CAT II
CCI(s)
- CCI-001464 - Initiates session audits automatically at system start-up.
- CCI-000018 - Automatically audit account creation actions.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001405 - Automatically audit account removal actions.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-002234 - Log the execution of privileged functions.
Weight
10
Fix Recommendation
Log in to the MKE web UI and navigate to admin >> Admin Settings >> Logs & Audit Logs.
In the "Configure Audit Log Level" section, select "Request"
In the "Configure Global Log Level" section, select "INFO" or "DEBUG".
Note: The recommended setting is "INFO".
Click "Save".
Check Contents
Check auditing configuration level for MKE nodes and controller:
Log in to the MKE web UI and navigate to admin >> Admin Settings >> Logs & Audit Logs.
If "AUDIT LOG LEVEL" is not set to "Request", this is a finding.
If "DEBUG LEVEL" is set to "ERROR", this is a finding.
Vulnerability Number
V-260914
Documentable
False
Rule Version
CNTR-MK-000220
Severity Override Guidance
Check auditing configuration level for MKE nodes and controller:
Log in to the MKE web UI and navigate to admin >> Admin Settings >> Logs & Audit Logs.
If "AUDIT LOG LEVEL" is not set to "Request", this is a finding.
If "DEBUG LEVEL" is set to "ERROR", this is a finding.
Check Content Reference
M
Target Key
5595