UCF STIG Viewer Logo

The ISSO must ensure application audit trails are retained for at least 1 year for applications without SAMI data, and 5 years for applications including SAMI data.


Overview

Finding ID Version Rule ID IA Controls Severity
V-70295 APSC-DV-002900 SV-84917r1_rule Medium
Description
Log files are a requirement to trace intruder activity or to audit user activity.
STIG Date
Application Security and Development Security Technical Implementation Guide 2018-12-24

Details

Check Text ( C-70771r1_chk )
Verify a process is in place to retain application audit log files for one year and five years for SAMI data.

If audit logs have not been retained for one year or five years for SAMI data, this is a finding.
Fix Text (F-76531r1_fix)
Retain application audit log files for one year and five years for SAMI data.