Open adammontville opened 5 years ago
Question: Are we requiring an alert when the setting is changed from its approved value, or only if the setting is still configured to the unapproved value at the time of the next scan?
UNCC Metrics: number of non-compliant settings number of unreported exceptions number of total config settings time between scans
Inputs:
Operations:
Measures:
Metrics:
NOTE This doesn't cover anything about alerts on unauthorized changes NOTE This sub-control is dependent on sub-control 5.1
Instead of using "subsequent" measurements, do measurements over a time period T
Utilize a Security Content Automation Protocol (SCAP) compliant configuration monitoring system to verify all security configuration elements, catalog approved exceptions, and alert when unauthorized changes occur.
Measures
Metrics