Rule ID
SV-7028r2_rule
Version
V2R15
CCIs
Without auditing the originator and destination of a fax cannot be determined. Prosecuting of an individual who maliciously compromises sensitive data via a fax will be hindered without audits.<br /><br />The SA will ensure auditing of user access and fax logging is enabled if fax from the network is enabled.
The reviewer will, with the assistance from the SA, verify auditing of user access and fax logging is enabled if fax from the network is enabled. If auditing of user access and fax logging is not enabled, this is a finding.
Configure the MFD to audit faxing. If this is not possible, disable the fax functionality and disconnect the phone line from the MFD.