SV-222472r508029_rule
V-222472
SRG-APP-000095
APSC-DV-000970
CAT II
10
Configure the application to log all changes to application data.
Review and monitor the application logs. When modifying data, the logs are most likely database logs.
If the application design documents include specific data elements that require protection, ensure any changes to those specific data elements are logged. Otherwise, a random check is sufficient.
If the application uses a database configured to use Transaction SQL logging this is not a finding if the application admin can demonstrate a process for reviewing the transaction log for data changes. The process must include using the transaction log and some form of query capability to identify users and the data they changed within the application and vice versa.
Utilize the application as a regular user and operate the application so as to modify a data element contained within the application.
Observe and determine if the application log includes an entry to indicate the users data change event was recorded.
If successful changes/modifications to application data elements are not recorded in the logs, this is a finding.
V-222472
False
APSC-DV-000970
Review and monitor the application logs. When modifying data, the logs are most likely database logs.
If the application design documents include specific data elements that require protection, ensure any changes to those specific data elements are logged. Otherwise, a random check is sufficient.
If the application uses a database configured to use Transaction SQL logging this is not a finding if the application admin can demonstrate a process for reviewing the transaction log for data changes. The process must include using the transaction log and some form of query capability to identify users and the data they changed within the application and vice versa.
Utilize the application as a regular user and operate the application so as to modify a data element contained within the application.
Observe and determine if the application log includes an entry to indicate the users data change event was recorded.
If successful changes/modifications to application data elements are not recorded in the logs, this is a finding.
M
4093