Check: WN12-AU-000203-02
Microsoft Windows Server 2012/2012 R2 Member Server STIG:
WN12-AU-000203-02
(in versions v3 r7 through v2 r7)
Title
The operating system must, at a minimum, off-load audit records of interconnected systems in real time and off-load standalone systems weekly. (Cat II impact)
Discussion
Protection of log data includes assuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration.
Check Content
Verify the operating system, at a minimum, off-loads audit records of interconnected systems in real time and off-loads standalone systems weekly. If it does not, this is a finding.
Fix Text
Configure the operating system to, at a minimum, off-load audit records of interconnected systems in real time and off-load standalone systems weekly.
Additional Identifiers
Rule ID: SV-225309r877390_rule
Vulnerability ID: V-225309
Group Title: SRG-OS-000342-GPOS-00133
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001851 |
The information system off-loads audit records per organization-defined frequency onto a different system or media than the system being audited. |
Controls
Number | Title |
---|---|
AU-4 (1) |
Transfer To Alternate Storage |