Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-37106 | SRG-NET-000100-FW-000061 | SV-48867r1_rule | Low |
Description |
---|
Logging the actions of specific events provides a means to investigate an attack, recognize resource utilization or capacity thresholds, or to simply identify an improperly configured system. Audit log data must be protected from unauthorized access, including from legitimate administrators who do not have a need for this type of access. Unauthorized deletion of logs or events may obfuscate evidence of an attack. Event log entries must not be deleted. |
STIG | Date |
---|---|
Firewall Security Requirements Guide | 2013-04-24 |
Check Text ( C-45478r1_chk ) |
---|
Verify a security policy for the audit logs is in place which allows only system administrators with the proper authorization to delete the audit log on the firewall. If audit logs are not protected from unauthorized deletion, this is a finding. |
Fix Text (F-42051r1_fix) |
---|
Create and implement an access control security policy to prevent unauthorized deletion of the audit logs on the firewall. |