The IAO/NSO will ensure a record is maintained of all logons and transactions processed by the management station. NOTE: Include time logged in and out, devices that were accessed and modified, and other activities performed.

From Network Devices Security Technical Implementation Guide

Part of Logons and transactions are not being recorded.

Associated with IA controls: ECSC-1, ECAR-3, ECAR-2, ECAR-1

SV-3050r1_rule The IAO/NSO will ensure a record is maintained of all logons and transactions processed by the management station. NOTE: Include time logged in and out, devices that were accessed and modified, and other activities performed.

Vulnerability discussion

Logging is a critical part of network security. Maintaining an audit trail of system activity logs can help identify configuration errors, understand past intrusions, troubleshoot service disruptions, and react to probes and scans of the network. Audit logs are also necessary to provide a trail of evidence in case the network is compromised. Without an audit trail that provides a when, where, who and how set of information, repeat offenders could continue attacks against the network indefinitely. With this information, the network administrator can devise ways to block the attack and possibly identify and prosecute the attacker.

Check content

Review the NMS configuration and logs

Fix text

The NSO will ensure that the NMS records all logons and transactions on the management station. The log will include at a minimum: time logged in and out, devices that were accessed and modified, and other activities performed. The audit will be stored online for a minimum of 30 days and offline for at least one year.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer