SV-222462r508029_rule
V-222462
SRG-APP-000503
APSC-DV-000830
CAT II
10
Configure the application or application server to write a log entry when successful and unsuccessful logon events occur.
Review and monitor the application logs.
Authenticate to the application and observe if the log includes an entry to indicate the user’s authentication was successful.
Terminate the user session by logging out.
Reauthenticate using invalid user credentials and observe if the log includes an entry to indicate the authentication was unsuccessful.
If successful and unsuccessful logon events are not recorded in the logs, this is a finding.
V-222462
False
APSC-DV-000830
Review and monitor the application logs.
Authenticate to the application and observe if the log includes an entry to indicate the user’s authentication was successful.
Terminate the user session by logging out.
Reauthenticate using invalid user credentials and observe if the log includes an entry to indicate the authentication was unsuccessful.
If successful and unsuccessful logon events are not recorded in the logs, this is a finding.
M
4093