The Riverbed NetIM must enable and configure user audit logging.
DISA Rule
SV-275452r1147406_rule
Vulnerability Number
V-275452
Group Title
SRG-APP-000028-NDM-000210
Rule Version
RIIM-DM-000002
Severity
CAT I
CCI(s)
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001405 - Automatically audit account removal actions.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-001464 - Initiates session audits automatically at system start-up.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-000166 - Provide irrefutable evidence that an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
- CCI-000187 - For public key-based authentication, map the authenticated identity to the account of the individual or group.
- CCI-000764 - Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- CCI-002130 - Automatically audit account enabling actions.
- CCI-000018 - Automatically audit account creation actions.
- CCI-002234 - Log the execution of privileged functions.
Weight
10
Fix Recommendation
Enable the User Audit role and assign to a user.
1. From the GUI, navigate to Configure >> All Settings >> Administer >> User Audit.
2. On the Settings tab, select "Yes" under the User Audit Logging section.
3. Assign the role to an admin user account.
Note: The user auditor role removes all other admin roles and functions from the users assigned the role of audit administrator. Other types of administrators, including the default admin of last resort, will not be able to access the auditing functions or local audit log.
Check Contents
Verify user audit logging is enabled.
1. From the GUI menu, navigate to Configure >> All Settings >> Administer >> User Audit.
2. Under the User Audit Logging section, verify "Yes" is selected.
If user audit logging is not enabled and assigned, this is a finding.
Vulnerability Number
V-275452
Documentable
False
Rule Version
RIIM-DM-000002
Severity Override Guidance
Verify user audit logging is enabled.
1. From the GUI menu, navigate to Configure >> All Settings >> Administer >> User Audit.
2. Under the User Audit Logging section, verify "Yes" is selected.
If user audit logging is not enabled and assigned, this is a finding.
Check Content Reference
M
Target Key
5704