Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35195 | SRG-APP-000113-AS-000073 | SV-46482r1_rule | Medium |
Description |
---|
Audit reduction is used to reduce the volume of audit records in order to facilitate manual review. Before a security review, the AS administrator may utilize the audit reduction capability to remove the audit records known to have little security significance. This is generally accomplished by filtering records generated by specified classes of events, such as records generated by nightly backups. Audit reduction does not alter the original audit records. An audit reduction capability provides support for near real-time audit review and analysis requirements and after-the-fact investigations of security incidents. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43572r1_chk ) |
---|
Review the AS product documentation and management interface to determine if the AS provides an audit reduction capability. If the AS does not provide audit reduction, this is a finding. |
Fix Text (F-39741r1_fix) |
---|
Configure the AS to provide and utilize audit reduction. |