Exchange Email Subject Line logging must be disabled.
From MS Exchange 2013 Mailbox Server Security Technical Implementation Guide
Part of SRG-APP-000098
Associated with:
CCI-000133
SV-84577r2_rule
Exchange Email Subject Line logging must be disabled.
Vulnerability discussion
Log files help establish a history of activities and can be useful in detecting attack attempts or determining tuning adjustments to improve availability. When “message tracking” is enabled, only the sender, recipients, time, and other delivery information are included by default. Information such as the subject and message body is not included.However, the absence of the message subject line can make it difficult to locate a specific message in the log unless one knows roughly what time the message was sent. To simplify searches through these logs, Exchange offers the ability to include the message “subject line” in the log files and in the Message Tracking Center display. This can make it significantly easier to locate a specific message.This feature creates larger log files and will contain information that may raise privacy and legal concerns. Enterprise policy should be consulted before this feature is enabled. Also, since the log files may contain sensitive information in the form of the subject line, the log files will need to be protected, commensurate with the sensitivity level, as the content may be of interest to an attacker. For these reasons, it is recommended that subject logging not be enabled during regular production operations. Instead, treat this feature as a diagnostic that can be used if needed. The tradeoff is that finding the correct message in the message tracking logs will become more difficult since the administrator will need to search using only the time the message was sent and the message’s sender. This control will have no effect unless Message Tracking is enabled. However, the setting should be disabled in case message tracking is enabled in the future.
Check content
Open the Exchange Management Shell and enter the following command:
Get-TransportService | Select Name, Identity, MessageTrackingLogSubjectLoggingEnabled
If the value of MessageTrackingLogSubjectLoggingEnabled is not set to “True”, this is a finding.
Fix text
Open the Exchange Management Shell and enter the following command:
Set-TransportService -Identity <'IdentityName'> - MessageTrackingLogSubjectLoggingEnabled $True
Note: The value must be in quotes.
Pro Tips
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer