STIGQter STIGQter: STIG Summary: Central Log Server Security Requirements Guide Version: 1 Release: 4 Benchmark Date: 24 Jul 2020:

The Central Log Server must be configured to perform audit reduction that supports after-the-fact investigations of security incidents.

DISA Rule

SV-95873r1_rule

Vulnerability Number

V-81159

Group Title

SRG-APP-000365-AU-000210

Rule Version

SRG-APP-000365-AU-000210

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the Central Log Server to perform audit reduction that supports after-the-fact investigations of security incidents.

Check Contents

Examine the configuration.

Verify the Central Log Server performs audit reduction that supports after-the-fact investigations of security incidents.

If the Central Log Server is not configured to perform audit reduction that supports after-the-fact investigations of security incidents, this is a finding.

Vulnerability Number

V-81159

Documentable

False

Rule Version

SRG-APP-000365-AU-000210

Severity Override Guidance

Examine the configuration.

Verify the Central Log Server performs audit reduction that supports after-the-fact investigations of security incidents.

If the Central Log Server is not configured to perform audit reduction that supports after-the-fact investigations of security incidents, this is a finding.

Check Content Reference

M

Target Key

3395

Comments