UCF STIG Viewer Logo

The application server must invoke a system shutdown in the event of an audit failure, unless an alternative audit capability exists.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35576 SRG-APP-000107-AS-NA SV-46863r1_rule Medium
Description
It is critical when a system is at risk of failing to process audit logs as required; it takes action to mitigate the failure. If the system were to continue processing without auditing enabled, actions can be taken on the system that cannot be tracked and recorded for later forensic analysis. Due to the critical services of the AS, the server should never be automatically shut down as that could cause an application DoS. This requirement is better met by utilizing AS failover or system monitoring capabilities.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43917r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-40118r1_fix)
The requirement is NA. No fix is required.