The CA API Gateway must protect audit information from unauthorized deletion.

From CA API Gateway ALG Security Technical Implementation Guide

Part of SRG-NET-000100-ALG-000058

Associated with: CCI-000164

SV-85963r1_rule The CA API Gateway must protect audit information from unauthorized deletion.

Vulnerability discussion

If audit data becomes compromised, forensic analysis and discovery of the true source of potentially malicious system activity is impossible to achieve.To ensure the veracity of audit data, the information system and/or the application must protect audit information from unauthorized modification. This requirement can be achieved through multiple methods, which will depend on system architecture and design. Some commonly employed methods include ensuring log files receive the proper file system permissions and limiting log data locations.Audit information includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully audit information system activity.Audited events are protected by default by only allowing access to the audited events to authorized users of the CA API Gateway - Policy Manager assigned to the role of "View Audit Records". Those users must be granted access by an administrator and must be approved for access to the audited events by the organization. Users needing access to the deletion of audited events must be explicitly granted the privileges to do so.

Check content

Open the CA API Gateway - Policy Manager. Select "Tasks" from the main menu and choose "Manage Roles". Verify that only authorized users have been given the "View Audit Records" role. If unauthorized users are granted this role, this is a finding.

Fix text

Open the CA API Gateway - Policy Manager as an administrator. Select "Tasks" from the main menu and chose "Manage Roles". Select the "View Audit Records" Role and Add/Assign the users that are authorized to view the audited events as per organizational policy.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer