Microsoft Defender for Endpoint (MDE) must be connected to a central log server.
DISA Rule
SV-272889r1119412_rule
Vulnerability Number
V-272889
Group Title
SRG-APP-000515
Rule Version
MSDE-00-000450
Severity
CAT I
CCI(s)
- CCI-001851 - Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging.
- CCI-000174 - Compile audit records from organization-defined information system components into a system-wide (logical or physical) audit trail that is time-correlated to within an organization-defined level of tolerance for relationship between time stamps of individual records in the audit trail.
- CCI-000139 - Alert organization-defined personnel or roles within an organization-defined time period in the event of an audit logging process failure.
- CCI-001348 - Store audit records on an organization-defined frequency in a repository that is part of a physically different system or system component that the system or component being audited.
- CCI-001876 - Provide an audit reduction capability that supports on-demand reporting requirements.
- CCI-003821 - Implement the capability to centrally review and analyze audit records from multiple components within the system.
Weight
10
Fix Recommendation
Access the MDE portal as a user with at least an MDE Administrator or equivalent role:
1. In the MDE portal select Settings >> Microsoft Sentinel.
2. Under Workspaces connect a Sentinel Workspace.
Check Contents
Access the MDE portal as a user with at least an MDE Administrator or equivalent role:
1. In the navigation pane, select Settings >> Microsoft Sentinel.
2. Under "Workspaces", verify a Sentinel Workspace has been assigned.
If a Sentinel Workspace has not been assigned, this is a finding.
If another documented and authorizing official (AO)-approved SIEM/Central Log Server is in use, this is not a finding.
Vulnerability Number
V-272889
Documentable
False
Rule Version
MSDE-00-000450
Severity Override Guidance
Access the MDE portal as a user with at least an MDE Administrator or equivalent role:
1. In the navigation pane, select Settings >> Microsoft Sentinel.
2. Under "Workspaces", verify a Sentinel Workspace has been assigned.
If a Sentinel Workspace has not been assigned, this is a finding.
If another documented and authorizing official (AO)-approved SIEM/Central Log Server is in use, this is not a finding.
Check Content Reference
M
Target Key
5693