Rule ID
SV-233047r960906_rule
Version
V2R4
CCIs
CCI-001487
Without information that establishes the identity of the user associated with the events, security personnel cannot determine responsibility for the potentially harmful event.
Review container platform documentation and the log files on the application server to determine if the logs contain information that establishes the identity of the user or process associated with log event data. If the container platform does not produce logs that establish the identity of the user or process associated with log event data, this is a finding.
Configure the container platform logging system to log the identity of the user or process related to the events.