STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 02 Jul 2025:

The F5 BIG-IP appliance must manage local audit storage capacity in accordance with organization-defined audit record storage requirements.

DISA Rule

SV-266074r1024605_rule

Vulnerability Number

V-266074

Group Title

SRG-APP-000357-NDM-000293

Rule Version

F5BI-DM-300033

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

To manage audit record storage capacity, configure the following log-related elements on the BIG-IP system in accordance with the site's System Security Plan:
- Change the log rotation frequency.
- Change the age at which log files become eligible for removal.
- Change the number of archive copies that the system retains.
- Change the message count for alertd log check.

Check Contents

Verify the site configures the local audit record storage capacity using any of the following log-related elements in accordance with the site's System Security Plan:
- Log rotation frequency.
- Age at which log files become eligible for removal.
- The number of archive copies that the system retains.
- The message count for alertd log check.

If the site does not manage log storage capacity in compliance with the SSP or if the process is not documented, this is a finding.

Vulnerability Number

V-266074

Documentable

False

Rule Version

F5BI-DM-300033

Severity Override Guidance

Verify the site configures the local audit record storage capacity using any of the following log-related elements in accordance with the site's System Security Plan:
- Log rotation frequency.
- Age at which log files become eligible for removal.
- The number of archive copies that the system retains.
- The message count for alertd log check.

If the site does not manage log storage capacity in compliance with the SSP or if the process is not documented, this is a finding.

Check Content Reference

M

Target Key

5639