Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35188 | SRG-APP-000109-AS-000069 | SV-46475r1_rule | Low |
Description |
---|
Audit processing failures include software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded. To ensure flexibility and ease of use, application servers must be capable of notifying a group of administrative personnel upon detection of an application audit log processing failure. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43567r1_chk ) |
---|
Review the organization policy and AS configuration settings to determine if the AS is configured to notify a group of administrative personnel when the audit subsystem fails to operate. If policy requires group notification and the AS is not configured to meet this requirement, this is a finding. |
Fix Text (F-39735r1_fix) |
---|
Configure the AS to notify a group of administrative staff when the auditing subsystem fails. |