Rule ID
SV-285271r1258720_rule
Version
V1R1
Predictable failure prevention requires organizational planning to address system failure issues. If components key to maintaining systems security fail to function, the system could continue operating in an insecure state. The organization must be prepared and the application must support requirements that specify if the application must alarm for such conditions and/or automatically shut down the application or the system. This can include conducting a graceful application shutdown to avoid losing information. Automatic or manual transfer of components from standby to active mode can occur, for example, upon detection of component failures. If a component such as the DNSSEC or TSIG/SIG(0) signing capabilities were to fail, the DNS server should shut itself down to prevent continued execution without the necessary security components in place. Transactions such as zone transfers would not be able to work correctly in this state.
Verify Infoblox external logging is configured such that when a component failure is detected, a notification is sent to the system administrator (SA). 1. Navigate to Infoblox Grid >> Grid Manager tab >> Grid Properties (Toolbar menu), or to System >> System Manager >> System Properties if using a stand-alone configuration. 2. Select the "Monitoring" tab. 3. Validate the checkbox for "Log to External Syslog Servers" is selected and that an External Syslog Server is configured. 4. Validate "Copy Audit Log Message to Syslog" is selected. 5. Review the "Notification" tab and validate the selection of Event Types for SNMP and Email notifications. 6. Review the "SNMP" and "Email" tabs to verify their respective configurations, as applicable. 7. When complete, click "Cancel" to exit the "Properties" screen. If notification to the SA are not configured, this is a finding.
1. Navigate to Infoblox Grid >> Grid Manager tab >> Grid Properties (Toolbar menu), or to System >> System Manager >> System Properties if using a stand-alone configuration. 2. Select the "Monitoring" tab. 3. Select "Log to External Syslog Server" checkbox and configure at least one External Syslog Server. 4. Select the option "Copy Audit Log Message to Syslog". 5. Review the "Notification" tab and enable the applicable Event Types for SNMP and Email notifications. 6. Navigate to the "SNMP" and "Email" tabs to configure their respective settings, as needed. Verify the configured notification email address is correct according to organizational policy or by consulting the system administrator. 7. Click "Save & Close" to save the changes and exit the "Properties" screen. 8. Perform a service restart if necessary.