AOS must audit the execution of privileged functions.
DISA Rule
SV-266950r1039871_rule
Vulnerability Number
V-266950
Group Title
SRG-APP-000343-NDM-000289
Rule Version
ARBA-ND-000289
Severity
CAT II
CCI(s)
- CCI-002234 - Log the execution of privileged functions.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
Weight
10
Fix Recommendation
Configure AOS with the following commands:
configure terminal
audit-trail all
write memory
Check Contents
Verify the AOS configuration with the following command:
show running-config | include audit-trail
If the audit-trail is not enabled, this is a finding.
Vulnerability Number
V-266950
Documentable
False
Rule Version
ARBA-ND-000289
Severity Override Guidance
Verify the AOS configuration with the following command:
show running-config | include audit-trail
If the audit-trail is not enabled, this is a finding.
Check Content Reference
M
Target Key
5648