MarkLogic Server DBMS must generate audit records when security objects are deleted.
An XCCDF Rule
Description
The removal of security objects from the database/DBMS would seriously degrade a system's information assurance posture. If such an event occurs, it must be logged.
- ID
- SV-220404r961818_rule
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure MarkLogic to produce audit records when security objects are deleted.
Perform the fix from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Groups icon.
2. Click the group in which the configuration to be checked resides (e.g., Default).