Check: WN16-AU-000020
Microsoft Windows Server 2016 STIG:
WN16-AU-000020
(in versions v2 r4 through v1 r1)
Title
Windows Server 2016 must, at a minimum, off-load audit records of interconnected systems in real time and off-load standalone systems weekly. (Cat II impact)
Discussion
Protection of log data includes assuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration.
Check Content
Verify the audit records, at a minimum, are off-loaded for interconnected systems in real time and off-loaded for standalone systems weekly. If they are not, this is a finding.
Fix Text
Configure the system to, at a minimum, off-load audit records of interconnected systems in real time and off-load standalone systems weekly.
Additional Identifiers
Rule ID: SV-88055r1_rule
Vulnerability ID: V-73403
Group Title: SRG-OS-000479-GPOS-00224
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001851 |
Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging. |
Controls
Number | Title |
---|---|
AU-4(1) |
Transfer to Alternate Storage |