SV-222512r508029_rule
V-222512
SRG-APP-000381
APSC-DV-001420
CAT II
10
Configure the application to create log entries that can be used to identify the user accounts that make application configuration changes.
Review the application documentation and configuration settings.
Access the application configuration settings interface as a privileged user.
Make configuration changes to the application.
Review the application audit logs and ensure a log entry is made identifying the privileged user account that was used to make the changes.
If application configuration is maintained by using a text editor to modify a configuration file, modify the configuration file with a text editor. Review the system logs and ensure a log entry is made for the file modification that identifies the user that was used to make the changes.
If the user account is not logged, or is a group account such as "root", this is a finding.
If the user account used to make the changes is not logged in the audit records, this is a finding.
V-222512
False
APSC-DV-001420
Review the application documentation and configuration settings.
Access the application configuration settings interface as a privileged user.
Make configuration changes to the application.
Review the application audit logs and ensure a log entry is made identifying the privileged user account that was used to make the changes.
If application configuration is maintained by using a text editor to modify a configuration file, modify the configuration file with a text editor. Review the system logs and ensure a log entry is made for the file modification that identifies the user that was used to make the changes.
If the user account is not logged, or is a group account such as "root", this is a finding.
If the user account used to make the changes is not logged in the audit records, this is a finding.
M
4093