Check: WN16-AU-000010
Microsoft Windows Server 2016 STIG:
WN16-AU-000010
(in versions v2 r9 through v1 r1)
Title
Audit records must be backed up to a different system or media than the system being audited. (Cat II impact)
Discussion
Protection of log data includes assuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration.
Check Content
Determine if a process to back up log data to a different system or media than the system being audited has been implemented. If it has not, this is a finding.
Fix Text
Establish and implement a process for backing up log data to another system or media other than the system being audited.
Additional Identifiers
Rule ID: SV-224875r958754_rule
Vulnerability ID: V-224875
Group Title: SRG-OS-000342-GPOS-00133
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001851 |
Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging. |
Controls
Number | Title |
---|---|
AU-4(1) |
Transfer to Alternate Storage |