STIGQter STIGQter: STIG Summary: Central Log Server Security Requirements Guide Version: 1 Release: 4 Benchmark Date: 24 Jul 2020:

For the host and devices within its scope of coverage, the Central Log Server must be configured to send a real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) of all audit failure events, such as loss of communications with hosts and devices, or if log records are no longer being received.

DISA Rule

SV-95863r1_rule

Vulnerability Number

V-81149

Group Title

SRG-APP-000360-AU-000130

Rule Version

SRG-APP-000360-AU-000130

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

For the host and devices within its scope of coverage, configure the Central Log Server to send an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events such as loss of communications with hosts and devices, or if log records are no longer being received.

Check Contents

Examine the configuration.

Verify the system is configured to send an alert to the SA and ISSO, within seconds or less, when communication is lost with any host or device within the scope of coverage that may indicate an audit failure.

Verify the system is configured to send an alert if hosts and devices stop sending log records to the Central Log Server.

If the Central Log Server is not configured to send a real-time alert to the SA and ISSO (at a minimum) of all audit failure events, this is a finding.

Vulnerability Number

V-81149

Documentable

False

Rule Version

SRG-APP-000360-AU-000130

Severity Override Guidance

Examine the configuration.

Verify the system is configured to send an alert to the SA and ISSO, within seconds or less, when communication is lost with any host or device within the scope of coverage that may indicate an audit failure.

Verify the system is configured to send an alert if hosts and devices stop sending log records to the Central Log Server.

If the Central Log Server is not configured to send a real-time alert to the SA and ISSO (at a minimum) of all audit failure events, this is a finding.

Check Content Reference

M

Target Key

3395

Comments