Rule version BCAS-ND-001860 · STIG v1 · 2026-09-16
Without comprehensive audit logging, organizations cannot establish, correlate, and investigate the events relating to a security incident or identify those responsible for unauthorized activities. If the network device fails to log critical security-relevant events—such as administrative logins, account modifications, privilege escalations, and system configuration changes—system administrators (SAs) and information system security officers (ISSOs) will lack the forensic evidence required to detect, analyze, and remediate cyber threats or insider abuses. Configuring the CAS to include all audit information ensures that a complete, DoW-compliant audit trail is generated and captured for all administrative and system-level actions.
Satisfies: SRG-APP-000516-NDM-000334, SRG-APP-000026-NDM-000208, SRG-APP-000027-NDM-000209, SRG-APP-000028-NDM-000210, SRG-APP-000029-NDM-000211, SRG-APP-000091-NDM-000223, SRG-APP-000095-NDM-000225, SRG-APP-000096-NDM-000226, SRG-APP-000097-NDM-000227, SRG-APP-000098-NDM-000228, SRG-APP-000099-NDM-000229, SRG-APP-000100-NDM-000230, SRG-APP-000101-NDM-000231, SRG-APP-000319-NDM-000283, SRG-APP-000343-NDM-000289, SRG-APP-000381-NDM-000305, SRG-APP-000495-NDM-000318, SRG-APP-000499-NDM-000319, SRG-APP-000503-NDM-000320, SRG-APP-000504-NDM-000321, SRG-APP-000505-NDM-000322, SRG-APP-000506-NDM-000323
Verify "logging include-audit-info" is set to "true" with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Run the command "show running-config logging". 4. Review the output for the setting "logging include-audit-info".
If the output is "false", or the setting is missing, this is a finding.
Configure "logging include-audit-info" to "true" with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and enter the password. 3. Enter "configure terminal". 4. Add the command to include all audit logs by entering "logging include-audit-info true". 5. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.