The application must record the username or user ID of the user associated with the event.
An XCCDF Rule
Description
<VulnDiscussion>When users conduct activity within an application, that user’s identity must be recorded in the audit log. Failing to record the identity of the user responsible for the activity within the application is detrimental to forensic analysis.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-222449r879559_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Configure the application to record the user ID of the user responsible for the log event entry.