STIGQter STIGQter: STIG Summary: Network Infrastructure Policy Security Technical Implementation Guide Version: 10 Release: 7 Benchmark Date: 24 Oct 2024:

Dynamic Host Configuration Protocol (DHCP) audit and event logs must record sufficient forensic data to be stored online for thirty days and offline for one year.

DISA Rule

SV-251361r853649_rule

Vulnerability Number

V-251361

Group Title

NET0198

Rule Version

NET0198

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DHCP audit and event logs to log hostname and MAC addresses, in addition to IP address and date/time.

Store the logs for a minimum of thirty days online and then offline for one year.

Check Contents

Verify the DHCP audit and event logs include hostnames and MAC addresses of all clients, in addition to IP address and date/time. Also, validate logs are kept online for thirty days and offline for one year.

If the logs do not include hostnames and MAC addresses along with the IP address and date/time, or if the logs are not kept online for thirty days and offline for one year, this is a finding.

Vulnerability Number

V-251361

Documentable

False

Rule Version

NET0198

Severity Override Guidance

Verify the DHCP audit and event logs include hostnames and MAC addresses of all clients, in addition to IP address and date/time. Also, validate logs are kept online for thirty days and offline for one year.

If the logs do not include hostnames and MAC addresses along with the IP address and date/time, or if the logs are not kept online for thirty days and offline for one year, this is a finding.

Check Content Reference

M

Target Key

5444