UCF STIG Viewer Logo

The DNS implementation must provide a real-time alert when organization defined audit failure events occur.


Overview

Finding ID Version Rule ID IA Controls Severity
V-33986 SRG-NET-000085-DNS-000044 SV-44439r1_rule Medium
Description
It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Audit processing failures include: software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded, and others as organizationally defined. When audit failures occur the DNS must send a real-time alarm to appropriate personnel. If personnel are not notified, appropriate action cannot be taken to restore the audit functionality. Without log records there is no traceability for forensic or analytical purposes. Without sufficient information establishing real time events, investigation into the cause of events is severely hindered.
STIG Date
Domain Name System (DNS) Security Requirements Guide 2012-10-24

Details

Check Text ( C-41990r1_chk )
Review the DNS system configuration to determine if a real time alert is generated and sent to appropriate personnel upon audit log failure. If a real-time alert is not sent upon occurrence of an audit failure, this is a finding.
Fix Text (F-37901r1_fix)
Configure the DNS system to send real-time alerts to appropriate personnel upon audit log failure.