STIGQter STIGQter: STIG Summary: Cloud Computing Mission Owner Operating System Security Requirements Guide Version: 1 Release: 3 Benchmark Date: 13 Aug 2025:

The Infrastructure as a Service (IaaS)/Platform as a Service (PaaS) must perform centralized logging to capture and store log records.

DISA Rule

SV-259876r958754_rule

Vulnerability Number

V-259876

Group Title

SRG-OS-000342

Rule Version

SRG-OS-000342-CLD-000020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This applies to all Impact Levels.
FedRAMP - Does not match DOD requirement explicitly. Allows up to seven days for offloading. Moderate, High.

Implement a solution for centralized logging to capture and store the log records produced on the IaaS/PaaS.

Check Contents

If this is a Software as a Service (SaaS) implementation, this is not a finding.

Verify the IaaS/PaaS is configured to use centralized logging to capture and store the log records produced by the virtual machine (VM) management on the IaaS/PaaS.

If the IaaS/PaaS does not perform centralized logging to capture and store the log records produced by the VM management, this is a finding.

Vulnerability Number

V-259876

Documentable

False

Rule Version

SRG-OS-000342-CLD-000020

Severity Override Guidance

If this is a Software as a Service (SaaS) implementation, this is not a finding.

Verify the IaaS/PaaS is configured to use centralized logging to capture and store the log records produced by the virtual machine (VM) management on the IaaS/PaaS.

If the IaaS/PaaS does not perform centralized logging to capture and store the log records produced by the VM management, this is a finding.

Check Content Reference

M

Target Key

5584