The Apache web server must use a logging mechanism that is configured to provide a warning to the Information System Security Officer (ISSO) and System Administrator (SA) when allocated record storage volume reaches 75 percent of maximum log record storage capacity.
DISA Rule
SV-214350r961398_rule
Vulnerability Number
V-214350
Group Title
SRG-APP-000359-WSR-000065
Rule Version
AS24-W1-000740
Severity
CAT II
CCI(s)
- CCI-001855 - Provide a warning to organization-defined personnel, roles, and/or locations within an organization-defined time period when allocated audit log storage volume reaches an organization-defined percentage of repository maximum audit log storage capacity.
Weight
10
Fix Recommendation
Work with the SIEM administrator to configure an alert when no audit data is received from Apache based on the defined schedule of connections.
Check Contents
Work with the SIEM administrator to determine if an alert is configured when audit data is no longer received as expected.
If there is no alert configured, this is a finding.
Vulnerability Number
V-214350
Documentable
False
Rule Version
AS24-W1-000740
Severity Override Guidance
Work with the SIEM administrator to determine if an alert is configured when audit data is no longer received as expected.
If there is no alert configured, this is a finding.
Check Content Reference
M
Target Key
3998