Skip to main content
CUI

Documentation - V-222416

V-222416

Application Security and Development Security Technical Implementation Guide

CAT II

Title

The application must automatically audit account removal actions.

Description

<VulnDiscussion>When application accounts are removed, user accessibility is affected. Accounts are utilized for identifying individual application users or for identifying the application processes themselves. In order to detect and respond to events affecting user accessibility and application processing, applications must audit account removal actions and, as required, notify the appropriate individuals, so they can investigate the event. Such a capability greatly reduces the risk that applic...

Fix Text (Documentation Requirement)

Configure the application to write a log entry when a user account is removed. At a minimum, ensure account name, date and time of the event are recorded.

Documentation Status

Cancel
CUI