Check: SRG-NET-000334-VVEP-00010
Enterprise Voice, Video, and Messaging Endpoint SRG:
SRG-NET-000334-VVEP-00010
(in versions v1 r2 through v1 r1)
Title
The Enterprise Voice, Video, and Messaging Endpoint must offload audit records onto a different system or media than the system being audited. (Cat II impact)
Discussion
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Offloading is a common process in information systems with limited audit storage capacity. Audit records are commonly produced by session management and border elements. Many Enterprise Voice, Video, and Messaging Endpoints are not capable of providing audit records and instead rely on session management and border elements. Enterprise Voice, Video, and Messaging Endpoints capable of producing audit records provide supplemental confirmation of monitored events. Enterprise Voice, Video, and Messaging Endpoints that support audit records must support offloading.
Check Content
Verify the Enterprise Voice, Video, and Messaging Endpoint offloads audit records onto a different system or media. If the Enterprise Voice, Video, and Messaging Endpoint does not offload audit records to a different system or media, this is a finding.
Fix Text
Configure the Enterprise Voice, Video, and Messaging Endpoint to offload audit records to a different system or media.
Additional Identifiers
Rule ID: SV-259970r948877_rule
Vulnerability ID: V-259970
Group Title: SRG-NET-000334
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001851 |
Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging. |
Controls
Number | Title |
---|---|
AU-4(1) |
Transfer to Alternate Storage |