V-222448
Application Security and Development Security Technical Implementation Guide
Title
The application must provide audit record generation capability for connecting system IP addresses.
Description
<VulnDiscussion>Without the capability to generate audit records, it would be difficult to establish, correlate, and investigate the events relating to an incident, or identify those responsible for one. Audit records can be generated from various components within the application (e.g., process, module). Certain specific application functionalities may be audited as well. The list of audited events is the set of events for which audits are to be generated. This set of events is typically a sub...
Fix Text (Documentation Requirement)
Configure the application or application server to log all connecting IP address information