SharePoint must identify potentially security-relevant error conditions.

From SharePoint 2010 Security Technical Implementation Guide (STIG)

Part of SRG-APP-000265-COL-000170

Associated with IA controls: DCBP-1

Associated with: CCI-001311

SV-36713r2_rule SharePoint must identify potentially security-relevant error conditions.

Vulnerability discussion

The error messages and usage data to be monitored should be carefully considered. The extent to which the application is able to identify and handle error conditions is guided by organizational policy and operational requirements. Usage and Health Data Collection Service Application collects data about usage and health of your farm. This information is used for Health Monitoring and this is also required for running the Web Analytics Service. If there is no Usage and Health Data Collection Service Application or the Usage and Health Data Collection Proxy is stopped, the Web Analytics Report will not show any data.SharePoint Usage and Health Data Collection Service Application must be enabled in order to detect potential security errors. The usage and health data settings are farm-wide and cannot be set for individual servers in the farm.

Check content

1. In SharePoint Central Administration, click Monitoring. 2. On the Monitoring page, in the Reporting list, click Configure usage and health data collection. 3. On the Configure web analytics and health data collection page, in the Usage Data Collection section, verify Enable usage data collection is checked. 4. In the Health Data Collection section, verify Enable health data collection is checked. 5. Mark as a finding if Enable usage data collection and Enable health data collection are not checked.

Fix text

Enable and configure the Usage and Health Data Collection Service Application. 1. In SharePoint Central Administration, click Monitoring. 2. On the Monitoring page, in the Reporting list, click Configure usage and health data collection. 3. On the Configure web analytics and health data collection page, in the Usage Data Collection section, check the box for Enable usage data collection. 4. In the Health Data Collection section, check the box for Enable health data collection. 5. Click OK.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer