The RUCKUS ICX device must initiate session auditing upon startup.
DISA Rule
SV-273788r1110839_rule
Vulnerability Number
V-273788
Group Title
SRG-APP-000092-NDM-000224
Rule Version
RCKS-NDM-000180
Severity
CAT II
CCI(s)
- CCI-001464 - Initiates session audits automatically at system start-up.
- CCI-000018 - Automatically audit account creation actions.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001405 - Automatically audit account removal actions.
- CCI-000166 - Provide irrefutable evidence that an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
- CCI-002130 - Automatically audit account enabling actions.
- CCI-002234 - Log the execution of privileged functions.
- CCI-003938 - Automatically generate audit records of the enforcement actions.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-000366 - Implement the security configuration settings.
Weight
10
Fix Recommendation
Enable logging:
SSH@ICX(config)# logging on
SSH@ICX(config)# exit
SSH@ICX# write memory
Check Contents
Verify that logging is enabled:
SSH@ICX(config)# show running-config | include logging
logging console
logging persistence
logging cli-command
logging host x.x.x.x
logging host y.y.y.y
If "no logging on" exists, this is a finding.
Vulnerability Number
V-273788
Documentable
False
Rule Version
RCKS-NDM-000180
Severity Override Guidance
Verify that logging is enabled:
SSH@ICX(config)# show running-config | include logging
logging console
logging persistence
logging cli-command
logging host x.x.x.x
logging host y.y.y.y
If "no logging on" exists, this is a finding.
Check Content Reference
M
Target Key
5695