SV-54197r3_rule
V-41620
SRG-APP-000100-WSR-000064
SRG-APP-000100-WSR-000064
CAT II
10
Configure the web server to include the user/subject identity or process as part of each log record.
Review the web server documentation and deployment configuration to determine if the web server can generate log data containing the user/subject identity.
Request a user access the hosted application and generate logable events, and verify the events contain the user/subject or process identity.
If the identity is not part of the log record, this is a finding.
V-41620
False
SRG-APP-000100-WSR-000064
Review the web server documentation and deployment configuration to determine if the web server can generate log data containing the user/subject identity.
Request a user access the hosted application and generate logable events, and verify the events contain the user/subject or process identity.
If the identity is not part of the log record, this is a finding.
M
2557