Check: 3.092
Windows XP STIG:
3.092
(in versions v6 r1.32 through v1 r0)
Title
The system does not generate an audit event when the audit log reaches a percent full threshold. (Cat III impact)
Discussion
When the audit log reaches a given percent full, an audit event is written to the security log. The event ID is 523 and is recorded as a success audit under the category of System. This option may be especially useful if the audit logs are set to be cleared manually. A recommended setting would be 90 percent.
Check Content
Analyze the system using the Security Configuration and Analysis snap-in. Expand the Security Configuration and Analysis tree view. Navigate to Local Policies -> Security Options. If the value for “MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning” is not set to “90” or less, then this is a finding. The policy referenced configures the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \System\CurrentControlSet\Services\Eventlog\Security\ Value Name: WarningLevel Value Type: REG_DWORD Value: 90 Documentable Explanation: If the system is configured to write to an audit server, or is configured to automatically archive full logs this should be documented with the IAO.
Fix Text
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> “MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning” to “90” or less.
Additional Identifiers
Rule ID: SV-4108r1_rule
Vulnerability ID: V-4108
Group Title: Audit Log Warning Level
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |