The Apache web server must use a logging mechanism that is configured to alert the Information System Security Officer (ISSO) and System Administrator (SA) in the event of a processing failure.
DISA Rule
SV-214234r960912_rule
Vulnerability Number
V-214234
Group Title
SRG-APP-000108-WSR-000166
Rule Version
AS24-U1-000160
Severity
CAT II
CCI(s)
- CCI-000139 - Alert organization-defined personnel or roles within an organization-defined time period in the event of an audit logging process failure.
- CCI-001855 - Provide a warning to organization-defined personnel, roles, and/or locations within an organization-defined time period when allocated audit log storage volume reaches an organization-defined percentage of repository maximum audit log storage capacity.
Weight
10
Fix Recommendation
Work with the SIEM administrator to configure an alert when no audit data is received from Apache based on the defined schedule of connections.
Check Contents
Work with the SIEM administrator to determine if an alert is configured when audit data is no longer received as expected.
If there is no alert configured, this is a finding.
Vulnerability Number
V-214234
Documentable
False
Rule Version
AS24-U1-000160
Severity Override Guidance
Work with the SIEM administrator to determine if an alert is configured when audit data is no longer received as expected.
If there is no alert configured, this is a finding.
Check Content Reference
M
Target Key
3996