NET0398 - The ISSO must ensure an acknowledgement message identifying a reference to the potential security violation is logged

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The ISSO must ensure an acknowledgement message identifying a reference to the potential security violation is logged and it contains a notice that it has been acknowledged, the time of the acknowledgement and the user identifier that acknowledged the alarm, at the remote administrator session that received the alarm.

Acknowledging the alert could be a single event, or different events. In addition, assurance is required that each administrator that received the alarm message also receives the acknowledgement message, which includes some form of reference to the alarm message, who acknowledged the message and when.

NOTE: Nessus did not perform this check as the Cisco ASA does not support all of the required features on the device itself. Utilizing a syslog server or SIEM product with advanced searching and alerting capabilities will greatly assist with this requirement.

Solution

Configure the firewall to send acknowledge messages to administrators, referencing the alarm, who acknowledged the alarm, and timestamps.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Firewall_V8R24_STIG.zip

Item Details

References: CAT|III, Rule-ID|SV-15282r2_rule, STIG-ID|NET0398, Vuln-ID|V-14656

Plugin: Cisco

Control ID: 7bf64026289e00819e3614a1d0a3369a3dc42639ba0a99ee39f014d9514564c2