Rule ID
SV-288238r1252299_rule
Version
V1R0.1
CCIs
If events associated with nonlocal administrative access or diagnostic sessions are not logged and audited, a major tool for assessing and investigating attacks would not be available. This requirement addresses auditing-related issues associated with maintenance tools used specifically for diagnostic and repair actions on organizational information systems. This requirement applies to hardware/software diagnostic test equipment or tools. This requirement does not cover hardware/software components that may support information system maintenance, yet are a part of the system (e.g., the software implementing "ping," "ls," "ipconfig," or the hardware and software implementing the monitoring port of an Ethernet switch).
If the application is not a maintenance application, this requirement is Not Applicable. Review the application's documentation and deployed configuration to determine whether the auditing mechanism generates organization-defined audit records for nonlocal maintenance and diagnostic sessions. If the application's auditing mechanism does not generate audit records for nonlocal maintenance and diagnostic session organization-defined audit events, this is a finding.
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to generate organization-defined audit records for nonlocal maintenance and diagnostic sessions.