STIGQter STIGQter: STIG Summary: Arista MLS DCS-7000 Series NDM Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 25 Oct 2019:

The Arista Multilayer Switch must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).

DISA Rule

SV-75325r1_rule

Vulnerability Number

V-60867

Group Title

SRG-APP-000374-NDM-000299

Rule Version

AMLS-NM-000290

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the network device to record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).

This can be configured with the following command:

clock timezone GMT

Check Contents

Determine if the network device records time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT). This requirement may be verified by demonstration or configuration review.

If the network device does not record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT), this is a finding.

This can be configured with the following command:

clock timezone GMT

and verified by

show run section clock

Log records can be validated with:

show logging

Vulnerability Number

V-60867

Documentable

False

Rule Version

AMLS-NM-000290

Severity Override Guidance

Determine if the network device records time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT). This requirement may be verified by demonstration or configuration review.

If the network device does not record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT), this is a finding.

This can be configured with the following command:

clock timezone GMT

and verified by

show run section clock

Log records can be validated with:

show logging

Check Content Reference

M

Target Key

2825

Comments