Check: WN12-AU-000203-02
Windows 2012 IAVM:
WN12-AU-000203-02
(in version v1 r30)
Title
The operating system must, at a minimum, off-load audit records of interconnected systems in real time and off-load standalone systems weekly. (Cat II impact)
Discussion
Protection of log data includes assuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration.
Check Content
Verify the operating system, at a minimum, off-loads audit records of interconnected systems in real time and off-loads standalone systems weekly. If it does not, this is a finding.
Fix Text
Configure the operating system to, at a minimum, off-load audit records of interconnected systems in real time and off-load standalone systems weekly.
Additional Identifiers
Rule ID:
Vulnerability ID: V-57719
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001851 |
Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging. |
Controls
Number | Title |
---|---|
AU-4(1) |
Transfer to Alternate Storage |