Check: SRG-APP-000358-CTR-000805
Container Platform SRG:
SRG-APP-000358-CTR-000805
(in versions v1 r5 through v1 r1)
Title
Audit records must be stored at a secondary location. (Cat II impact)
Discussion
Auditable events are used in the investigation of incidents and must be protected from being deleted or altered. Often, events that took place in the past must be viewed to understand the entire incident. For the purposes of audit event protection and recall, audit events are often off-loaded to an external storage location. The container platform must provide a mechanism to assist in the off-loading of the audit data or at a minimum, must not hinder an external process used for audit event off-loading.
Check Content
Verify the log records are being off-loaded to a separate system or transferred from the container platform storage location to a storage location other than the container platform itself. The information system may demonstrate this capability using a log management application, system configuration, or other means. If logs are not being off-loaded, this is a finding.
Fix Text
Configure the container platform to off-load the logs to a remote log or management server.
Additional Identifiers
Rule ID: SV-233169r879731_rule
Vulnerability ID: V-233169
Group Title: SRG-APP-000358
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001851 |
The information system off-loads audit records per organization-defined frequency onto a different system or media than the system being audited. |
Controls
Number | Title |
---|---|
AU-4 (1) |
Transfer To Alternate Storage |