Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-70295 | APSC-DV-002900 | SV-84917r1_rule | Medium |
Description |
---|
Log files are a requirement to trace intruder activity or to audit user activity. |
STIG | Date |
---|---|
Application Security and Development Security Technical Implementation Guide | 2017-03-20 |
Check Text ( C-70771r1_chk ) |
---|
Verify a process is in place to retain application audit log files for one year and five years for SAMI data. If audit logs have not been retained for one year or five years for SAMI data, this is a finding. |
Fix Text (F-76531r1_fix) |
---|
Retain application audit log files for one year and five years for SAMI data. |