Rule ID
SV-288209r1252765_rule
Version
V1R0.1
Without information about the outcome of events, security personnel cannot make an accurate assessment as to whether an attack was successful or if changes were made to the security state of the system. Event outcomes can include indicators of event success or failure and event-specific results (e.g., the security state of the information system after the event occurred). As such, they also provide a means to measure the impact of an event and help authorized personnel to determine the appropriate response. Organizations log system accesses associated with applying configuration changes to ensure configuration change control is implemented and to support after-the-fact actions should organizations discover any unauthorized changes.
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism produces audit records that contain information to establish success indicators, fail indicators, and enforcement actions. If the application's auditing mechanism does not produce audit records that contain information to establish success indicators, fail indicators, and enforcement actions, this is a finding.
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to produce audit records that contain information to establish success indicators, fail indicators, and enforcement actions.