STIGQter STIGQter: STIG Summary: IBM DataPower ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Jan 2016:

The DataPower Gateway providing content filtering must send an alert to, at a minimum, the ISSO and ISSM when detection events occur.

DISA Rule

SV-79783r1_rule

Vulnerability Number

V-65293

Group Title

SRG-NET-000392-ALG-000141

Rule Version

WSDP-AG-000113

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the DataPower WebGUI, navigate to Administration >> Access >> SNMP Settings. Configure the "Trap Event Subscriptions" tab to include Event Subscriptions that are judged to be associated with detection incidents. Configure the "Trap and Notification Targets" tab to include an SNMP server.

The administrator can also configure a Log Target to send event information to other logging/monitoring solutions, including Syslog.

To configure a Syslog Log Target, type "Log Target" in to the Search bar >> Select "Log Targets" from the results list >> Click Add >> Configure a Log Target of type "syslog" >> Configure specific event subscriptions to be sent to the Syslog Server.

Check Contents

In the DataPower web interface, navigate to Administration >> Access >> SNMP Settings. Verify that the desired event codes are included on the "Trap Event Subscriptions" tab.

Type "Log Target" in to the Search bar >> Select "Log Targets" from the results list >> Select the desired Log Target >> Verify that the desired event codes are included in the Event Subscriptions tab.

If no Log Target is configured or the assigned event codes are not included, this is a finding.

Vulnerability Number

V-65293

Documentable

False

Rule Version

WSDP-AG-000113

Severity Override Guidance

In the DataPower web interface, navigate to Administration >> Access >> SNMP Settings. Verify that the desired event codes are included on the "Trap Event Subscriptions" tab.

Type "Log Target" in to the Search bar >> Select "Log Targets" from the results list >> Select the desired Log Target >> Verify that the desired event codes are included in the Event Subscriptions tab.

If no Log Target is configured or the assigned event codes are not included, this is a finding.

Check Content Reference

M

Target Key

2859

Comments