From IBM WebSphere Traditional V9.x Security Technical Implementation Guide
Part of SRG-APP-000016-AS-000013
Associated with: CCI-000067 CCI-000130 CCI-000132 CCI-000133 CCI-000134 CCI-000135 CCI-000169 CCI-000172 CCI-001462 CCI-001487 CCI-001814 CCI-002234
Logging must be utilized in order to track system activity, assist in diagnosing system issues, and provide evidence needed for forensic investigations post security incident.
In the administrative console, navigate to Security >> Security auditing >> Event type Filters. Verify the following events and outcomes are enabled in the "Events and Outcomes" box. Also note the name of the filter associated with these events. This name will be referenced in STIG ID WBSP-AS-000110. AUTHN: SUCCESS,INFO,WARNING,ERROR,DENIED,REDIRECT AUTHZ: SUCCESS,INFO,WARNING,ERROR,DENIED,REDIRECT AUTHN_TERMINATE: SUCCESS,INFO,WARNING,ERROR,DENIED,REDIRECT REPOSITORY_SAVE: SUCCESS,INFO,WARNING,ERROR,DENIED,REDIRECT If these audit filters are not configured in "Events and Outcomes", this is a finding.
In the administrative console, navigate to Security >> Security auditing >> Event type Filters. Click the "New" button to create a new filter; give it a unique name. Select SECURITY_AUTHN, SECURITY_AUTHZ, SECURITY_AUTHN_TERMINATE, and ADMIN_REPOSITORY_SAVE from "Selectable events". Add them to the "Enabled events" box by clicking on the right arrow. Select INFO, ERROR, SUCCESS, DENIED, REDIRECT, and WARNING from the "Selectable event outcomes" box. Click the right arrow to fill in "Enabled events outcomes" box. Click "OK". Restart the DMGR and all the JVMs.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer