AOS must automatically audit account creation.
DISA Rule
SV-266908r1039745_rule
Vulnerability Number
V-266908
Group Title
SRG-APP-000026-NDM-000208
Rule Version
ARBA-ND-000208
Severity
CAT II
CCI(s)
- CCI-000018 - Automatically audit account creation actions.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001405 - Automatically audit account removal actions.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-002130 - Automatically audit account enabling actions.
Weight
10
Fix Recommendation
Configure AOS with the following commands:
configure terminal
logging security level debug
write memory
Check Contents
Verify the AOS configuration with the following command:
show logging level
If the security logging level is not set to debug, this is a finding.
Vulnerability Number
V-266908
Documentable
False
Rule Version
ARBA-ND-000208
Severity Override Guidance
Verify the AOS configuration with the following command:
show logging level
If the security logging level is not set to debug, this is a finding.
Check Content Reference
M
Target Key
5648