Skip to content

The SDN controller must be configured to produce audit records containing information to establish when the events occurred.

An XCCDF Rule

Description

Without establishing when events occurred, it is impossible to establish, correlate, and investigate the events leading up to an outage or attack. In order to compile an accurate risk assessment, and provide forensic analysis of network traffic patterns, it is essential for security personnel to know when (i.e., date and time) flow control events occurred within the infrastructure.

ID
SV-206718r382858_rule
Version
SRG-NET-000075-SDN-000125
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the SDN controller to include the date and time in the log records.