Skip to content

II - Mission Support Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000097-DB-000041

    Group
  • PostgreSQL must produce audit records containing sufficient information to establish where the events occurred.

    Information system auditing capability is critical for accurate forensic analysis. Without establishing where events occurred, it is impossible to establish, correlate, and investigate the events r...
    Rule Medium Severity
  • SRG-APP-000441-DB-000378

    Group
  • PostgreSQL must maintain the confidentiality and integrity of information during preparation for transmission.

    Information can be either unintentionally or maliciously disclosed or modified during preparation for transmission, including, for example, during aggregation, at protocol transformation points, an...
    Rule Medium Severity
  • SRG-APP-000089-DB-000064

    Group
  • PostgreSQL must be configured to provide audit record generation for DoD-defined auditable events within all DBMS/database components.

    Without the capability to generate audit records, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one. Audit re...
    Rule Medium Severity
  • SRG-APP-000375-DB-000323

    Group
  • PostgreSQL must generate time stamps, for audit records and application data, with a minimum granularity of one second.

    Without sufficient granularity of time stamps, it is not possible to adequately determine the chronological order of records. Time stamps generated by PostgreSQL must include date and time. Granu...
    Rule Medium Severity
  • SRG-APP-000100-DB-000201

    Group
  • PostgreSQL must produce audit records containing sufficient information to establish the identity of any user/subject or process associated with the event.

    Information system auditing capability is critical for accurate forensic analysis. Without information that establishes the identity of the subjects (i.e., users or processes acting on behalf of us...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules