STIGQter STIGQter: STIG Summary: Intrusion Detection and Prevention Systems (IDPS) Security Requirements Guide Version: 2 Release: 6 Benchmark Date: 24 Jul 2020:

In the event of a logging failure, caused by loss of communications with the central logging server, the IDPS must queue audit records locally until communication is restored or until the audit records are retrieved manually or using automated synchronization tools.

DISA Rule

SV-69579r1_rule

Vulnerability Number

V-55333

Group Title

SRG-NET-000089-IDPS-00010

Rule Version

SRG-NET-000089-IDPS-00010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the IDPS, in the event of a logging failure caused by loss of communications with the central logging server, to queue audit records locally until communication is restored or until the audit records are retrieved manually or using automated synchronization tools.

Check Contents

Verify the IDPS, in the event of a logging failure caused by loss of communications with the central logging server, queues audit records locally until communication is restored or until the audit records are retrieved manually or using automated synchronization tools.

In the event of a logging failure caused by loss of communications with the central logging server, if the IDPS does not queue audit records locally until communication is restored or until the audit records are retrieved manually or using automated synchronization tools, this is a finding.

Vulnerability Number

V-55333

Documentable

False

Rule Version

SRG-NET-000089-IDPS-00010

Severity Override Guidance

Verify the IDPS, in the event of a logging failure caused by loss of communications with the central logging server, queues audit records locally until communication is restored or until the audit records are retrieved manually or using automated synchronization tools.

In the event of a logging failure caused by loss of communications with the central logging server, if the IDPS does not queue audit records locally until communication is restored or until the audit records are retrieved manually or using automated synchronization tools, this is a finding.

Check Content Reference

M

Target Key

2358

Comments