Check: EMG3-037 EMail
Email Services Policy STIG:
EMG3-037 EMail
(in version v2 r6)
Title
Email audit trails must be reviewed daily. (Cat III impact)
Discussion
Access to email servers and software are logged to establish a history of actions taken in the system. Unauthorized access or use of the system could indicate an attempt to bypass established permissions. Reviewing the log history can lead to discovery of unauthorized access attempts. Reviewing the logs daily helps to ensure prompt attention is given to any suspicious activities discovered therein.
Check Content
Review the audit trail review procedures in the EDSP. Examine artifacts of log reviews (results) and review frequency. If Audit trail review procedures and evidence of review results exist, this is not a finding.
Fix Text
Document audit record review procedures in the EDSP. Implement audit record daily reviews as documented.
Additional Identifiers
Rule ID: SV-20654r3_rule
Vulnerability ID: V-18869
Group Title: EMG3-037 Audit Trail Reviews
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |