Skip to content

Application Server Security Requirements Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The application server must produce log records containing sufficient information to establish when (date and time) the events occurred.

    Application server logging capability is critical for accurate forensic analysis. Without sufficient and accurate information, a correct replay of the events cannot be determined. Ascertaining th...
    Rule Medium Severity
  • SRG-APP-000097

    Group
  • SRG-APP-000098

    Group
  • SRG-APP-000099

    Group
  • SRG-APP-000100

    Group
  • The application server must generate log records containing information that establishes the identity of any individual or process associated with the event.

    Information system logging capability is critical for accurate forensic analysis. Log record content that may be necessary to satisfy the requirement of this control includes: time stamps, source a...
    Rule Medium Severity
  • SRG-APP-000101

    Group
  • SRG-APP-000108

    Group
  • The application server must alert the SA and ISSO, at a minimum, in the event of a log processing failure.

    Logs are essential to monitor the health of the system, investigate changes that occurred to the system, or investigate a security incident. When log processing fails, the events during the failur...
    Rule Medium Severity
  • SRG-APP-000116

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules