Check: WN12-AU-000203-01
Microsoft Windows Server 2012/2012 R2 Domain Controller STIG:
WN12-AU-000203-01
(in versions v3 r7 through v2 r7)
Title
Audit records must be backed up onto a different system or media than the system being audited. (Cat II impact)
Discussion
Protection of log data includes assuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration.
Check Content
Determine if a process to back up log data to a different system or media than the system being audited has been implemented. If it has not, this is a finding.
Fix Text
Establish and implement a process for backing up log data to another system or media other than the system being audited.
Additional Identifiers
Rule ID: SV-226123r877390_rule
Vulnerability ID: V-226123
Group Title: SRG-OS-000342-GPOS-00133
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001851 |
The information system off-loads audit records per organization-defined frequency onto a different system or media than the system being audited. |
Controls
Number | Title |
---|---|
AU-4 (1) |
Transfer To Alternate Storage |