Rule ID
SV-288206r1252756_rule
Version
V1R0.1
CCIs
Without information about the outcome of events, security personnel cannot make an accurate assessment as to whether an attack was successful or if changes were made to the security state of the system. Event outcomes can include indicators of event success or failure and event-specific results (e.g., event descriptions such as what type of event occurred). As such, they also provide a means to measure the impact of an event and help authorized personnel to determine the appropriate response. Organizations log system accesses associated with applying configuration changes to ensure that configuration change control is implemented and to support after-the-fact actions should organizations discover any unauthorized changes.
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism produces audit records containing descriptions of the audit events. If the application's auditing mechanism does not produce audit records containing descriptions of the audit events, this is a finding.
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to produce audit records containing descriptions of the audit events.