Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35199 | SRG-APP-000115-AS-000075 | SV-46486r1_rule | Medium |
Description |
---|
Audit reduction is used to reduce the volume of audit records in order to facilitate manual review. Before a security review information systems and/or applications with an audit reduction capability may remove many audit records known to have little security significance. This is generally accomplished by removing records generated by specified classes of events, such as records generated by nightly backups or other events deemed inconsequential to the investigation. Audit reduction does not alter or delete original audit records. When conducting a security review, time is often of the essence. A manual audit reduction capability is too time consuming. The AS must provide an automated audit reduction capability that automatically filters out events based upon a selection of available event types. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43574r1_chk ) |
---|
Review the AS product documentation and management interface to determine if the AS provides the ability to filter out audit events based upon event criteria. If the AS does not provide the ability to filter out audit events based upon event criteria, this is a finding. |
Fix Text (F-39744r1_fix) |
---|
Configure the AS to filter out events based upon selectable event criteria. |