SV-85961r1_rule
V-71337
SRG-NET-000098-ALG-000056
CAGW-GW-000240
CAT II
10
Open the CA API Gateway - Policy Manager as an administrator.
Select "Tasks" from the main menu and chose "Manage Roles".
Remove the unauthorized user from any role they should not be a member of, including the "View Audit Records" role.
Additionally, consider removing the user completely or removing the user from any groups within the identity provider that may be assigned to a role for which the user may not be authorized.
Open the CA API Gateway - Policy Manager.
Select "Tasks" from the main menu and chose "Manage Roles". Verify that only authorized users have been given the "View Audit Records" role.
If unauthorized users are granted this role, this is a finding.
V-71337
False
CAGW-GW-000240
Open the CA API Gateway - Policy Manager.
Select "Tasks" from the main menu and chose "Manage Roles". Verify that only authorized users have been given the "View Audit Records" role.
If unauthorized users are granted this role, this is a finding.
M
3049