STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 2 Release: 3 Benchmark Date: 26 Apr 2019:

The web server must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.

DISA Rule

SV-54197r3_rule

Vulnerability Number

V-41620

Group Title

SRG-APP-000100-WSR-000064

Rule Version

SRG-APP-000100-WSR-000064

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the web server to include the user/subject identity or process as part of each log record.

Check Contents

Review the web server documentation and deployment configuration to determine if the web server can generate log data containing the user/subject identity.

Request a user access the hosted application and generate logable events, and verify the events contain the user/subject or process identity.

If the identity is not part of the log record, this is a finding.

Vulnerability Number

V-41620

Documentable

False

Rule Version

SRG-APP-000100-WSR-000064

Severity Override Guidance

Review the web server documentation and deployment configuration to determine if the web server can generate log data containing the user/subject identity.

Request a user access the hosted application and generate logable events, and verify the events contain the user/subject or process identity.

If the identity is not part of the log record, this is a finding.

Check Content Reference

M

Target Key

2557

Comments