STIGQter STIGQter: STIG Summary: Cisco ASA NDM Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Cisco ASA must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.

DISA Rule

SV-239922r961392_rule

Vulnerability Number

V-239922

Group Title

SRG-APP-000357-NDM-000293

Rule Version

CASA-ND-000920

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the buffer size for logging as shown in the example below.

ASA(config)# logging flash-maximum-allocation nnnnnnn
ASA(config)# logging flash-minimum-free nnnnnnn

Check Contents

Verify the Cisco ASA is configured with a logfile size. The configuration should look like the example below.

logging flash-bufferwrap
logging flash-minimum-free nnnnnnn
logging flash-maximum-allocation nnnnnnn

If the Cisco ASA is not configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements, this is a finding.

Vulnerability Number

V-239922

Documentable

False

Rule Version

CASA-ND-000920

Severity Override Guidance

Verify the Cisco ASA is configured with a logfile size. The configuration should look like the example below.

logging flash-bufferwrap
logging flash-minimum-free nnnnnnn
logging flash-maximum-allocation nnnnnnn

If the Cisco ASA is not configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements, this is a finding.

Check Content Reference

M

Target Key

5342