The Cisco ACI must automatically audit account creation.
DISA Rule
SV-271939r1114173_rule
Vulnerability Number
V-271939
Group Title
SRG-APP-000026-NDM-000208
Rule Version
CACI-ND-000024
Severity
CAT II
CCI(s)
- CCI-000018 - Automatically audit account creation actions.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001405 - Automatically audit account removal actions.
- CCI-002234 - Log the execution of privileged functions.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-002130 - Automatically audit account enabling actions.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
Weight
10
Fix Recommendation
To change the logging level to 6:
1. Select a service from the "Services" field in the "Changing Logging Level" window.
2. Choose the new logging level for the service from the "Logging Level" field.
3. Click "Apply".
Check Contents
View the AAA event types in the local log:
1. In the menu bar, click "Admin".
2. In the submenu bar, click "AAA".
3. In the Navigation pane, choose "AAA Authentication".
4. In the Work pane, click the "History" tab.
5. Under the History tab, click the "Events" subtab to view the event log.
6. Under the History tab, click the "Audit Log" subtab to view the audit log.
7. Double-click a log entry to view additional details about the event.
If account change actions are not being logged, this is a finding.
Vulnerability Number
V-271939
Documentable
False
Rule Version
CACI-ND-000024
Severity Override Guidance
View the AAA event types in the local log:
1. In the menu bar, click "Admin".
2. In the submenu bar, click "AAA".
3. In the Navigation pane, choose "AAA Authentication".
4. In the Work pane, click the "History" tab.
5. Under the History tab, click the "Events" subtab to view the event log.
6. Under the History tab, click the "Audit Log" subtab to view the audit log.
7. Double-click a log entry to view additional details about the event.
If account change actions are not being logged, this is a finding.
Check Content Reference
M
Target Key
5682