STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 2 Release: 3 Benchmark Date: 26 Apr 2019:

The web server must not impede the ability to write specified log record content to an audit log server.

DISA Rule

SV-70223r2_rule

Vulnerability Number

V-55969

Group Title

SRG-APP-000358-WSR-000063

Rule Version

SRG-APP-000358-WSR-000063

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the web server to directly write or transfer the logs to a remote audit log server.

Check Contents

Review the web server documentation and deployment configuration to determine if the web server can write log data to, or if log data can be transferred to, a separate audit server.

Request a user access the hosted application and generate logable events and verify the data is written to a separate audit server.

If logs cannot be directly written or transferred on request or on a periodic schedule to an audit log server, this is a finding.

Vulnerability Number

V-55969

Documentable

False

Rule Version

SRG-APP-000358-WSR-000063

Severity Override Guidance

Review the web server documentation and deployment configuration to determine if the web server can write log data to, or if log data can be transferred to, a separate audit server.

Request a user access the hosted application and generate logable events and verify the data is written to a separate audit server.

If logs cannot be directly written or transferred on request or on a periodic schedule to an audit log server, this is a finding.

Check Content Reference

M

Target Key

2557

Comments