Information
Security auditing must be configured in order to log remote session activity. Security auditing will not be performed unless the audit feature (audit-1.0) has been enabled. The security feature (appSecurity-2.0) must be enabled for the security auditing to capture security transactions. Remote session activity will then be logged, regardless of the user attempting that activity.
Satisfies: SRG-APP-000016-AS-000013, SRG-APP-000080-AS-000045, SRG-APP-000089-AS-000050, SRG-APP-000091-AS-000052, SRG-APP-000095-AS-000056, SRG-APP-000096-AS-000059, SRG-APP-000097-AS-000060, SRG-APP-000098-AS-000061, SRG-APP-000099-AS-000062, SRG-APP-000100-AS-000063, SRG-APP-000101-AS-000072, SRG-APP-000266-AS-000168, SRG-APP-000343-AS-000030, SRG-APP-000172-AS-000121
Solution
To log remote access events, the featureManager setting in the ${server.config.dir}/server.xml must contain the audit and appSecurity features.
<featureManager>
<feature>audit-1.0</feature>
<feature>appSecurity-2.0</feature>
</featureManager>
Item Details
Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY
References: 800-53|AC-6(9), 800-53|AC-17(1), 800-53|AU-3, 800-53|AU-3(1), 800-53|AU-9, 800-53|AU-10, 800-53|AU-12a., 800-53|AU-12c., 800-53|SI-11a., CAT|II, CCI|CCI-000067, CCI|CCI-000130, CCI|CCI-000131, CCI|CCI-000132, CCI|CCI-000133, CCI|CCI-000134, CCI|CCI-000135, CCI|CCI-000162, CCI|CCI-000166, CCI|CCI-000169, CCI|CCI-000172, CCI|CCI-001312, CCI|CCI-001487, CCI|CCI-002234, Rule-ID|SV-250325r1015250_rule, STIG-ID|IBMW-LS-000040, Vuln-ID|V-250325
Control ID: 4ab99ca61c7aac4f84ab8c1685768dba72011bfb2532663fb2b132393305fac3