5.3 Ensure that logging captures as much information as possible

Information

The SystemLog.quiet option stops logging of information such as:
connection events
authentication events
replication sync activities
evidence of some potentially impactful commands being run (eg: drop, dropIndexes, validate)
This information should be logged whenever possible. This check is only for Enterprise editions.
Rationale:
The use of SystemLog.quiet makes troubleshooting problems and investigating possible security incidents much more difficult.

Solution

Set SystemLog.quiet to False in the /etc/mongod.conf file to disable it.

See Also

https://workbench.cisecurity.org/files/1705

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c., CSCv6|6.2

Plugin: Unix

Control ID: e0d36b916a2ad7e1f5b73406acd46d63d967ad507b0e0090a0006d9f32afd0fd