Rule ID
SV-288208r1252762_rule
Version
V1R0.1
CCIs
Without information about the outcome of events, security personnel cannot make an accurate assessment as to whether an attack was successful or if changes were made to the security state of the system. Event outcomes can include indicators of event success or failure and event-specific results (e.g., source and destination addresses). As such, they also provide a means to measure the impact of an event and help authorized personnel to determine the appropriate response. Organizations log system accesses associated with applying configuration changes to ensure configuration change control is implemented and to support after-the-fact actions should organizations discover any unauthorized changes.
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism produces audit records containing information to establish source and destination addresses. If the application's auditing mechanism does not produce audit records containing information to establish source and destination addresses, this is a finding.
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to produce audit records containing information to establish source and destination addresses.