SV-222552r508029_rule
V-222552
SRG-APP-000177
APSC-DV-001830
CAT II
10
Configure the application to map certificate information to individual users or group accounts or create a process for automatically determining the individual user or group based on certificate information provided in the logs.
Review the application documentation and interview the application administrator to identify how the application maps individual user certificates or group accounts to individual users.
Access the application as a regular user while reviewing the application logs to determine if the application records the individual name of the user or if the application only includes certificate information.
If the application only logs certificate information which contains no discernable user data, ask the system admin what their process is for mapping the certificate information to the user.
If the application does not map the certificate data to an individual user or group, or if the administrator has no automated process established for determining the identity of the user, this is a finding.
V-222552
False
APSC-DV-001830
Review the application documentation and interview the application administrator to identify how the application maps individual user certificates or group accounts to individual users.
Access the application as a regular user while reviewing the application logs to determine if the application records the individual name of the user or if the application only includes certificate information.
If the application only logs certificate information which contains no discernable user data, ask the system admin what their process is for mapping the certificate information to the user.
If the application does not map the certificate data to an individual user or group, or if the administrator has no automated process established for determining the identity of the user, this is a finding.
M
4093