Check: 1.010
Windows 2003 MS STIG:
1.010
(in version v6 r37)
Title
An Auditors group has not been created to restrict access to the Windows Event Logs. (Cat II impact)
Discussion
The Security Event Log contains information on security exceptions that occur on the system. This data is critical for identifying security vulnerabilities and intrusions. The Application and System logs can also contain information that is critical in assessing security events. Therefore, these logs must be protected from unauthorized access and modification. An Auditors group will be used to restrict access to auditing through the User Right “Manage auditing and security log” (V-1103) and for assigning permissions to event logs (V-1077). Only individuals who have auditing responsibilities (IAO, IAM, auditors, etc.) should be members of this group. The individual System Administrators responsible for maintaining this system can also be members of this group.
Check Content
Interview the SA to determine if an Auditors group for controlling the Windows Event Logs has been created. NOTE: The administrator(s) responsible for the installation and maintenance of the individual system(s) must be a member(s) of the Auditors group. This will permit the responsible administrator to enable and configure system auditing, and perform maintenance functions related to the logs. Administrators who are not responsible for maintenance on an individual system will not be included in the Auditors group.
Fix Text
Create an Auditors group for controlling the Windows Event Logs and assign the necessary rights and access controls.
Additional Identifiers
Rule ID: SV-29777r1_rule
Vulnerability ID: V-1137
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000171 |
Allow organization-defined personnel or roles to select the event types that are to be logged by specific components of the system. |
Controls
Number | Title |
---|---|
AU-12 |
Audit Generation |