Check: WN16-AU-000010
Microsoft Windows Server 2016 STIG:
WN16-AU-000010
(in versions v2 r8 through v1 r1)
Title
Audit records must be backed up to a different system or media than the system being audited. (Cat II impact)
Discussion
Protection of log data includes assuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration.
Check Content
Determine if a process to back up log data to a different system or media than the system being audited has been implemented. If it has not, this is a finding.
Fix Text
Establish and implement a process for backing up log data to another system or media other than the system being audited.
Additional Identifiers
Rule ID: SV-224875r877390_rule
Vulnerability ID: V-224875
Group Title: SRG-OS-000342-GPOS-00133
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001851 |
The information system off-loads audit records per organization-defined frequency onto a different system or media than the system being audited. |
Controls
Number | Title |
---|---|
AU-4 (1) |
Transfer To Alternate Storage |