SV-222467r508029_rule
V-222467
SRG-APP-000509
APSC-DV-000880
CAT II
10
Configure the application to log user account creation, modification, disabling, and termination events.
Log on to the application as an administrative user.
Navigate to the user account management functionality. If no user management capability exists within the application, refer to the Enterprise Active Directory or LDAP user management interfaces.
Monitor and review the log where the application's user activity is recorded.
Create an application test account and then review the log to ensure a log record that documents the event is created.
Modify the test account and then review the log to ensure a log record that documents the event is created.
Disable the test account and then review the log to ensure a log record that documents the event is created.
Terminate/Remove the test account and then review the log to ensure a log record that documents the event is created.
If log events are not created that document all of these events, this is a finding.
If some, but not all of the aforementioned events are documented in the logs, this is a finding.
Findings should document which of the events was not logged.
V-222467
False
APSC-DV-000880
Log on to the application as an administrative user.
Navigate to the user account management functionality. If no user management capability exists within the application, refer to the Enterprise Active Directory or LDAP user management interfaces.
Monitor and review the log where the application's user activity is recorded.
Create an application test account and then review the log to ensure a log record that documents the event is created.
Modify the test account and then review the log to ensure a log record that documents the event is created.
Disable the test account and then review the log to ensure a log record that documents the event is created.
Terminate/Remove the test account and then review the log to ensure a log record that documents the event is created.
If log events are not created that document all of these events, this is a finding.
If some, but not all of the aforementioned events are documented in the logs, this is a finding.
Findings should document which of the events was not logged.
M
4093