STIGQter STIGQter: STIG Summary: Application Security and Development Security Technical Implementation Guide Version: 5 Release: 1 Benchmark Date: 23 Oct 2020:

The application must generate audit records when concurrent logons from different workstations occur.

DISA Rule

SV-222672r508029_rule

Vulnerability Number

V-222672

Group Title

SRG-APP-000506

Rule Version

APSC-DV-003360

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the application to log concurrent logons from different workstations.

Check Contents

Review the application documentation and interview the application administrator to identify where log records are stored.

Access log records then log on to the application as a regular user from one workstation. Take note of workstation IP address and confirm the address as the source workstation.

Have the application administrator log on to the application from another workstation using the same account.

Validate the IP address of the second workstation is recorded in the logs.

If the application does not create an audit record when concurrent logons occur from different workstations, this is a finding.

Vulnerability Number

V-222672

Documentable

False

Rule Version

APSC-DV-003360

Severity Override Guidance

Review the application documentation and interview the application administrator to identify where log records are stored.

Access log records then log on to the application as a regular user from one workstation. Take note of workstation IP address and confirm the address as the source workstation.

Have the application administrator log on to the application from another workstation using the same account.

Validate the IP address of the second workstation is recorded in the logs.

If the application does not create an audit record when concurrent logons occur from different workstations, this is a finding.

Check Content Reference

M

Target Key

4093

Comments