UCF STIG Viewer Logo

The DNS implementation must be configured to send an alert to designated personnel in the event of an audit processing failure.


Overview

Finding ID Version Rule ID IA Controls Severity
V-33989 SRG-NET-000088-DNS-000047 SV-44442r1_rule Medium
Description
It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Audit processing failures include: software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded, and others as organizationally defined. When audit processing failures occur the DNS must send an alert to appropriate personnel. If personnel are not notified, appropriate action cannot be taken to restore the audit functionality. Without log records there is no traceability for forensic or analytical purposes. Without sufficient information establishing real time events, investigation into the cause of events is severely hindered.
STIG Date
Domain Name System (DNS) Security Requirements Guide 2012-10-24

Details

Check Text ( C-41993r1_chk )
Review the DNS system configuration to determine if an alert (e.g., email) is generated and sent to appropriate personnel upon audit log processing failure. If an alert is not configured to be sent upon occurrence of an audit processing failure, this is a finding.
Fix Text (F-37904r1_fix)
Configure the DNS system to send an alert to appropriate personnel upon audit log processing failure.