Skip to content
Catalogs
XCCDF
Application Server Security Requirements Guide
SRG-APP-000100
The application server must generate log records containing information that establishes the identity of any individual or process associated with the event.
The application server must generate log records containing information that establishes the identity of any individual or process associated with the event. An XCCDF Rule
The application server must generate log records containing information that establishes the identity of any individual or process associated with the event.
Medium Severity
<VulnDiscussion>Information system logging capability is critical for accurate forensic analysis. Log record content that may be necessary to satisfy the requirement of this control includes: time stamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, filenames involved, and access control or flow control rules invoked.
Application servers have differing levels of logging capabilities that can be specified by setting a verbosity level. The application server must, at a minimum, be capable of establishing the identity of any user or process that is associated with any particular event.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>