STIGQter STIGQter: STIG Summary: IBM MQ Appliance v9.0 NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 05 Jun 2017:

The MQ Appliance network device must back up audit records at least every seven days onto a different system or system component than the system or component being audited.

DISA Rule

SV-89613r1_rule

Vulnerability Number

V-74939

Group Title

SRG-APP-000125-NDM-000241

Rule Version

MQMH-ND-000430

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log on to the MQ Appliance CLI as a privileged user.

Configure a syslog target.

To enter global configuration mode, enter "config".

To create a syslog target, enter:
logging target <logging target name>
type syslog
admin-state enabled
local-address <MQ Appliance IP>
remote-address <syslog server IP>
remote-port <syslog server port>
event audit info
event auth notice
event mgmt notice
event cli notice
event user notice
event system error
exit
write mem
y

Check Contents

Log on to the MQ Appliance CLI as a privileged user.

Enter:
co
show logging target

All configured logging targets will be displayed. Verify:
- This list of log targets includes an appropriate syslog notification target;
- The log target is enabled; and
- It includes all desired log event source and log level parameters, e.g., event audit debug.

If any of these conditions is not true, this is a finding.

Vulnerability Number

V-74939

Documentable

False

Rule Version

MQMH-ND-000430

Severity Override Guidance

Log on to the MQ Appliance CLI as a privileged user.

Enter:
co
show logging target

All configured logging targets will be displayed. Verify:
- This list of log targets includes an appropriate syslog notification target;
- The log target is enabled; and
- It includes all desired log event source and log level parameters, e.g., event audit debug.

If any of these conditions is not true, this is a finding.

Check Content Reference

M

Target Key

3243

Comments