Check: WN12-AU-000200
Microsoft Windows Server 2012/2012 R2 Member Server STIG:
WN12-AU-000200
(in versions v3 r7 through v2 r7)
Title
Audit data must be reviewed on a regular basis. (Cat II impact)
Discussion
To be of value, audit logs from critical systems must be reviewed on a regular basis. Critical systems should be reviewed on a daily basis to identify security breaches and potential weaknesses in the security structure. This can be done with the use of monitoring software or other utilities for this purpose.
Check Content
Determine whether audit logs are reviewed on a predetermined schedule. If audit logs are not reviewed on a regular basis, this is a finding.
Fix Text
Review audit logs on a predetermined scheduled.
Additional Identifiers
Rule ID: SV-225306r569185_rule
Vulnerability ID: V-225306
Group Title: SRG-OS-000255-GPOS-00096
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
CM-6 |
Configuration Settings |