STIGQter STIGQter: STIG Summary: Redis Enterprise 6.x Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

Redis Enterprise DBMS must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.

DISA Rule

SV-251195r961392_rule

Vulnerability Number

V-251195

Group Title

SRG-APP-000357-DB-000316

Rule Version

RD6X-00-005500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure that the server is configured with enough storage space to accommodate database and audit record storage. The right amount of storage will be dependent on a variety of factors such as: number of databases, database size, HA enabled, persistence enabled, etc.

At no time should storage be more than 95 percent full.

See the following documents for hardware requirements:
https://docs.redislabs.com/latest/rs/administering/designing-production/hardware-requirements/
and
https://docs.redislabs.com/latest/rs/installing-upgrading/file-locations/

Check Contents

Review organization documentation to determine the organization-defined audit record storage requirements. By default, Redis Enterprise will use whatever disk space is allocated for audit logs. It is the responsibility of the organization to ensure that the RHEL OS server hosting the service has been allocated enough storage space to avoid running out of log space.

Interview the system administrator and review audit log configuration and alerts to investigate whether there have been any incidents where the Redis Enterprise server ran out of audit log space since the last time the space was allocated, or other corrective measures were taken.

If such incidents have occurred, this is a finding.

Review the Redis Enterprise control pane as an admin user.

If alerts are present indicating that storage is full or is at 95 percent full, this is a finding.

Vulnerability Number

V-251195

Documentable

False

Rule Version

RD6X-00-005500

Severity Override Guidance

Review organization documentation to determine the organization-defined audit record storage requirements. By default, Redis Enterprise will use whatever disk space is allocated for audit logs. It is the responsibility of the organization to ensure that the RHEL OS server hosting the service has been allocated enough storage space to avoid running out of log space.

Interview the system administrator and review audit log configuration and alerts to investigate whether there have been any incidents where the Redis Enterprise server ran out of audit log space since the last time the space was allocated, or other corrective measures were taken.

If such incidents have occurred, this is a finding.

Review the Redis Enterprise control pane as an admin user.

If alerts are present indicating that storage is full or is at 95 percent full, this is a finding.

Check Content Reference

M

Target Key

5443