The Nokia router must initiate session auditing upon startup.
DISA Rule
SV-283765r1203340_rule
Vulnerability Number
V-283765
Group Title
SRG-APP-000092-NDM-000224
Rule Version
NOKI-ND-000170
Severity
CAT II
CCI(s)
- CCI-001464 - Initiates session audits automatically at system start-up.
- CCI-000018 - Automatically audit account creation actions.
- CCI-001403 - Automatically audit account modification actions.
- CCI-001404 - Automatically audit account disabling actions.
- CCI-001405 - Automatically audit account removal actions.
- CCI-000166 - Provide irrefutable evidence that an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-000130 - Ensure that audit records containing information that establishes what type of event occurred.
- CCI-000131 - Ensure that audit records containing information that establishes when the event occurred.
- CCI-000132 - Ensure that audit records containing information that establishes where the event occurred.
- CCI-000133 - Ensure that audit records containing information that establishes the source of the event.
- CCI-000134 - Ensure that audit records containing information that establishes the outcome of the event.
- CCI-001487 - Ensure that audit records containing information that establishes the identity of any individuals, subjects, or objects/entities associated with the event.
- CCI-000135 - Generate audit records containing the organization-defined additional information that is to be included in the audit records.
- CCI-002130 - Automatically audit account enabling actions.
- CCI-002234 - Log the execution of privileged functions.
- CCI-003938 - Automatically generate audit records of the enforcement actions.
- CCI-000169 - Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 a. on organization-defined information system components.
- CCI-000366 - Implement the security configuration settings.
Weight
10
Fix Recommendation
Configure appropriate logs:
- exit all
- configure log log-id <id>
- from main, security, and change
- to <console, syslog-id, snmp, log-file-id, memory, session, netconf, cli>
Note: Select the appropriate location for the log event data from the options above.
Check Contents
Verify at least one log file has been created with the "Source" field set to main, security, and change:
show log log-id
Event Logs
Name
Log Source Filter Admin Oper Logged Dropped Dest Dest Size
Id Id State State Type Id
101 M S C N/A up up 1420 0 netconf 500
If no log file has been created with "Source" including "M", "S", and "C" for main, security, and change events, this is a finding.
If "Admin State" and "Oper State" are "down", this is a finding.
Vulnerability Number
V-283765
Documentable
False
Rule Version
NOKI-ND-000170
Severity Override Guidance
Verify at least one log file has been created with the "Source" field set to main, security, and change:
show log log-id
Event Logs
Name
Log Source Filter Admin Oper Logged Dropped Dest Dest Size
Id Id State State Type Id
101 M S C N/A up up 1420 0 netconf 500
If no log file has been created with "Source" including "M", "S", and "C" for main, security, and change events, this is a finding.
If "Admin State" and "Oper State" are "down", this is a finding.
Check Content Reference
M
Target Key
5744