SV-222448r508029_rule
V-222448
SRG-APP-000089
APSC-DV-000690
CAT II
10
Configure the application or application server to log all connecting IP address information
Review the application documentation and interview the application administrator to identify where audit logs are stored.
Review audit logs and determine if the IP address information of systems that connect to the application is kept in the logs.
If connecting IP addresses are not seen in the logs, connect to the application remotely and review the logs to determine if the connection was logged.
If the IP addresses of the systems that connect to the application are not recorded in the logs, this is a finding.
V-222448
False
APSC-DV-000690
Review the application documentation and interview the application administrator to identify where audit logs are stored.
Review audit logs and determine if the IP address information of systems that connect to the application is kept in the logs.
If connecting IP addresses are not seen in the logs, connect to the application remotely and review the logs to determine if the connection was logged.
If the IP addresses of the systems that connect to the application are not recorded in the logs, this is a finding.
M
4093