Email software installation account usage must be logged.

From Email Services Policy STIG

Part of EMG3-028 Installation Account Usage Logged

Associated with IA controls: ECPA-1

SV-20652r3_rule Email software installation account usage must be logged.

Vulnerability discussion

Email Administrator or application owner accounts are granted more enhanced privileges than non-privileged users. It is especially important to grant access to privileged accounts to only those persons who are qualified and authorized to use them. Each use of the account should be logged to demonstrate this accountability.

Check content

Access the EDSP to verify logging procedure for software installation account usage. Examine evidence that logging is done for use of the correct account for email software installations and upgrades. If email software installation account usage is logged, this is not a finding.

Fix text

Implement a logging procedure for use of the email software installation account. Document it in the EDSP.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer