STIGQter STIGQter: STIG Summary: IBM DataPower ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Jan 2016:

The DataPower Gateway providing user access control intermediary services must provide the capability for authorized users to capture, record, and log all content related to a selected user session.

DISA Rule

SV-79795r1_rule

Vulnerability Number

V-65305

Group Title

SRG-NET-000399-ALG-000042

Rule Version

WSDP-AG-000120

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the WebGUI Control Panel, click on Troubleshooting >> Click on the Debug Probe tab >> Select a desired service type and service instance >> Click on Add Probe to begin tracking transaction information for that service instance.

From the WebGUI, go to Objects >> Logging Configuration >> Log Target. Configure the desired filters, triggers, subscriptions, and log destination.

Check Contents

From the WebGUI Control Panel, click on Troubleshooting >> Click on the Debug Probe tab. Verify that the desired service type and service instance has an active Probe track transaction information for that service instance.

From the WebGUI, go to Objects >> Logging Configuration>> Log Target. Verify the desired filters, triggers, subscriptions, and log destination.

If these items have not been configured, this is a finding.

Vulnerability Number

V-65305

Documentable

False

Rule Version

WSDP-AG-000120

Severity Override Guidance

From the WebGUI Control Panel, click on Troubleshooting >> Click on the Debug Probe tab. Verify that the desired service type and service instance has an active Probe track transaction information for that service instance.

From the WebGUI, go to Objects >> Logging Configuration>> Log Target. Verify the desired filters, triggers, subscriptions, and log destination.

If these items have not been configured, this is a finding.

Check Content Reference

M

Target Key

2859

Comments