The Apache web server must generate, at a minimum, log records for system startup and shutdown, system access, and system authentication events.
DISA Rule
SV-214310r505936_rule
Vulnerability Number
V-214310
Group Title
SRG-APP-000089-WSR-000047
Rule Version
AS24-W1-000070
Severity
CAT II
CCI(s)
- CCI-000169 - The information system provides audit record generation capability for the auditable events defined in AU-2 a. at organization-defined information system components.
- CCI-001464 - The information system initiates session audits at system start-up.
Weight
10
Fix Recommendation
Uncomment the "log_config_module" module line in the <'INSTALL PATH'>\conf\httpd.conf file.
Restart the Apache service.
Check Contents
In a command line, navigate to "<'INSTALLED PATH'>\bin". Run "httpd -M" to view a list of installed modules.
If the "log_config_module" is not enabled, this is a finding.
Vulnerability Number
V-214310
Documentable
False
Rule Version
AS24-W1-000070
Severity Override Guidance
In a command line, navigate to "<'INSTALLED PATH'>\bin". Run "httpd -M" to view a list of installed modules.
If the "log_config_module" is not enabled, this is a finding.
Check Content Reference
M
Target Key
3998
Comments