Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-999999-FW-000196 | SRG-NET-999999-FW-000196 | SRG-NET-999999-FW-000196_rule | Low |
Description |
---|
Event logging is a key function of the firewall implementation. Logging the actions of specific events provides a means to investigate an attack, recognize resource utilization or capacity thresholds, or to simply identify an improperly configured network element. It is imperative the firewall implementation is configured to allocate enough log record storage capacity that will not become exhausted. Without this capability, the site could lose valuable data needed for investigating security incidents. |
STIG | Date |
---|---|
Firewall Security Requirements Guide | 2012-12-10 |
Check Text ( C-SRG-NET-999999-FW-000196_chk ) |
---|
Verify a mechanism controlling the spooling of the firewall application log data to a central log server. Verify spooling is configured to move the data from the event log to the central log before the firewall log capacity is exceeded. If the logging function is not configured to reduce the risk of exceeding log capacity, this is a finding. |
Fix Text (F-SRG-NET-999999-FW-000196_fix) |
---|
Configure the firewall implementation to spool the log data before data overflow occurs. |