STIGQter STIGQter: STIG Summary: Akamai KSD Service Impact Level 2 NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 12 Sep 2017:

The Akamai Luna Portal must automatically audit account enabling actions.

DISA Rule

SV-91171r1_rule

Vulnerability Number

V-76475

Group Title

SRG-APP-000319-NDM-000283

Rule Version

AKSD-DM-000016

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Enable Luna Event notifications.

1. Log in to the Luna Portal as an administrator.
2. Select Configure >> Alerts.
3. Click the "Create New Alert" button.
4. Select "Luna Control Center Event" and press the "Next" button.
5. Check the box that reads "Manage - Manage Users".
6. Proceed through the alert creation wizard, filling out the appropriate fields, and then click "Submit".

Check Contents

Verify that the portal is sending Luna Event notifications:

1. Log in to the Luna Portal as an administrator.
2. Select Configure >> Alerts.
3. Search/filter for "Luna Control Center Event".
4. Click on "account enabling".
5. Verify that the following settings are selected by clicking the "Settings" button:
"Manage - Manage Users".

If the Luna Control Center event notifications are not enabled, this is a finding.

Vulnerability Number

V-76475

Documentable

False

Rule Version

AKSD-DM-000016

Severity Override Guidance

Verify that the portal is sending Luna Event notifications:

1. Log in to the Luna Portal as an administrator.
2. Select Configure >> Alerts.
3. Search/filter for "Luna Control Center Event".
4. Click on "account enabling".
5. Verify that the following settings are selected by clicking the "Settings" button:
"Manage - Manage Users".

If the Luna Control Center event notifications are not enabled, this is a finding.

Check Content Reference

M

Target Key

3167

Comments