UCF STIG Viewer Logo

The DBMS must have allocated audit record storage capacity.


Overview

Finding ID Version Rule ID IA Controls Severity
V-32256 SRG-APP-000072-DB-000046 SV-42573r1_rule Medium
Description
Applications need to be cognizant of potential audit log storage capacity issues. During the installation and/or configuration process, applications should detect and determine if adequate storage capacity has been allocated for audit logs. During the installation process, a notification may be provided to the installer indicating, based on the auditing configuration chosen and the amount of storage space allocated for audit logs, the amount of storage capacity available is not sufficient enough to meet storage requirements. When insufficient space in directories is allocated for audit records, database audit logs can fill up and begin to overwrite earlier logs, database activity can stop altogether, or auditing could fail and crucial tracking data could be lost.
STIG Date
Database Security Requirements Guide 2012-07-02

Details

Check Text ( C-40765r1_chk )
Verify storage capacity for audit records generated by the database. If no storage space is specifically allocated for database audit records, this is a finding.
Fix Text (F-36180r1_fix)
Specifically allocate appropriate storage space for audit logs.