UCF STIG Viewer Logo

Applications must generate audit records for the DoD selected list of auditable events.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35282 SRG-APP-000091-MAPP-NA SV-46569r1_rule Medium
Description
Audit records can be generated from various components within the information system. The list of audited events is the set of events for which audits are to be generated. This set of events is typically a subset of the list of all events for which the system is capable of generating audit records (i.e., auditable events). DoD shall select the list of auditable events and applications must generate audit records for those events. Rationale for non-applicability: The MOS SRG contains a requirement for logging application startup and a number of other security critical events. No further audit logging must be coded into each application running on the MOS, but application developers may do so for application-specific concerns.
STIG Date
Mobile Application Security Requirements Guide 2013-01-04

Details

Check Text ( C-43651r1_chk )
This requirement is NA for the MAPP SRG.
Fix Text (F-39828r1_fix)
The requirement is NA. No fix is required.