UCF STIG Viewer Logo

Email audit trails must be reviewed daily.


Overview

Finding ID Version Rule ID IA Controls Severity
V-18869 EMG3-037 EMail SV-20654r3_rule ECAT-1 Low
Description
Access to email servers and software are logged to establish a history of actions taken in the system. Unauthorized access or use of the system could indicate an attempt to bypass established permissions. Reviewing the log history can lead to discovery of unauthorized access attempts. Reviewing the logs daily helps to ensure prompt attention is given to any suspicious activities discovered therein.
STIG Date
Email Services Policy STIG 2015-08-07

Details

Check Text ( C-22677r5_chk )
Review the audit trail review procedures in the EDSP. Examine artifacts of log reviews (results) and review frequency.

If Audit trail review procedures and evidence of review results exist, this is not a finding.
Fix Text (F-19573r2_fix)
Document audit record review procedures in the EDSP. Implement audit record daily reviews as documented.