NET0396 - The ISSO must ensure an alert will remain written on the consoles until acknowledged by an administrator.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Critical alerts require immediate response. Critical alerts must not roll off the screens. The requirements are necessary to ensure an administrator will be aware of the alerts or alarm. The intent is to ensure that if an administrator is physically at the remote workstation the message will remain displayed until they have acknowledged it.

NOTE: Nessus did not perform this check as manual review is required. Determine the appropriate alerts and notifications performed as required by your organization. Utilizing a syslog server or SIEM product with advanced searching and alerting capabilities will greatly assist with this requirement.

Solution

Configure the firewall to send an alarm or retain an alert message until acknowledged.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Firewall_V8R24_STIG.zip

Item Details

References: CAT|III, Rule-ID|SV-15281r2_rule, STIG-ID|NET0396, Vuln-ID|V-14655

Plugin: Cisco

Control ID: 3799f1eb0edea80a2acb2e577b4063538690cd37ded073596fc52bceb2374421