STIGUI
V-76483CAT III Low severitySV-91179r1_rule

The Akamai Luna Portal must generate audit records when successful/unsuccessful attempts to access privileges occur.

Rule version AKSD-DM-000022 · STIG v1 · 2017-09-15

Discussion

Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an incident or identify those responsible for one.

Audit records can be generated from various components within the information system (e.g., module or policy filter).

Check

Verify that the portal is sending Luna Event notifications:

1. Log in to the Luna Portal as an administrator. 2. Select Configure >> Alerts. 3. Search/filter for "Luna Control Center Event". 4. Click on the event name that meets the criteria above. 5. Verify that the applicable events are selected by clicking the "Settings" button.

If the Luna Control Center event notifications are not enabled, this is a finding.

Fix

Enable Luna Event notifications:

1. Log in to the Luna Portal as an administrator. 2. Select Configure >> Alerts. 3. Click the "Create New Alert" button. 4. Select "Luna Control Center Event" and press the "Next" button. 5. Check the applicable boxes. 6. Proceed through the alert creation wizard, filling out the appropriate fields, and then click "Submit".

Identifiers

Group ID
V-76483
Group title
SRG-APP-000091-NDM-000223
Rule ID
SV-91179r1_rule
Check ID
C-76143r1_chk
Fix ID
F-83161r1_fix