STIGQter STIGQter: STIG Summary: Authentication, Authorization, and Accounting Services (AAA) Security Requirements Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2020:

AAA Services must be configured to queue audit records locally until communication is restored when any audit processing failure occurs.

DISA Rule

SV-95585r1_rule

Vulnerability Number

V-80875

Group Title

SRG-APP-000109-AAA-000310

Rule Version

SRG-APP-000109-AAA-000310

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AAA Services to queue audit records locally until communication is restored when any audit processing failure occurs. Some specific implementations may further require automatically restarting the audit service to synchronize the local audit data with the collection server. In some cases, AAA Services may require the audit records to be retrieved manually in the event of audit failure.

Check Contents

Verify AAA Services are configured to queue audit records locally when any audit processing failure occurs. The queuing must continue until communication is restored or until the audit records are retrieved manually. Some specific implementations may further require automatically restarting the audit service to synchronize the local audit data with the collection server.

If AAA Services are not configured to queue audit records locally until communication is restored when any audit processing failure occurs, this is a finding.

Vulnerability Number

V-80875

Documentable

False

Rule Version

SRG-APP-000109-AAA-000310

Severity Override Guidance

Verify AAA Services are configured to queue audit records locally when any audit processing failure occurs. The queuing must continue until communication is restored or until the audit records are retrieved manually. Some specific implementations may further require automatically restarting the audit service to synchronize the local audit data with the collection server.

If AAA Services are not configured to queue audit records locally until communication is restored when any audit processing failure occurs, this is a finding.

Check Content Reference

M

Target Key

3357

Comments