SV-90895r1_rule
V-76207
SRG-APP-000516-NDM-000334
CACT-NM-000010
CAT III
10
Configure CounterACT to generate audit log events for a locally developed list of auditable events.
1. Open the CounterACT Console.
2. Select Tools >> Options >> Plugin.
3. Select the Syslog Plugin.
4. Select CounterACT or the Enterprise Manager appliance you would like to verify.
5. Ensure additional settings for audit are available by ensuring that either one of these options is selected: "Include only messages generated by the 'send message to syslog action'" or "include NAC policy logs".
Determine if CounterACT generates audit log events for a locally developed list of auditable events.
1. Open the CounterACT Console.
2. Select Tools >> Options >> Plugin.
3. Select the Syslog Plugin.
4. Select CounterACT or the Enterprise Manager appliance you would like to verify.
5. Verify additional settings for audit are available by ensuring that either one of these options is selected: "Include only messages generated by the 'send message to syslog action'" or "include NAC policy logs".
If CounterACT is not configured to generate audit log events for a locally developed list of auditable events, this is a finding.
V-76207
False
CACT-NM-000010
Determine if CounterACT generates audit log events for a locally developed list of auditable events.
1. Open the CounterACT Console.
2. Select Tools >> Options >> Plugin.
3. Select the Syslog Plugin.
4. Select CounterACT or the Enterprise Manager appliance you would like to verify.
5. Verify additional settings for audit are available by ensuring that either one of these options is selected: "Include only messages generated by the 'send message to syslog action'" or "include NAC policy logs".
If CounterACT is not configured to generate audit log events for a locally developed list of auditable events, this is a finding.
M
3225