Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-246841 | HYCU-AU-000018 | SV-246841r768187_rule | Medium |
Description |
---|
It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without a real-time alert, security personnel may be unaware of an impending failure of the audit capability and system operation may be adversely affected. |
STIG | Date |
---|---|
HYCU for Nutanix Security Technical Implementation Guide | 2021-08-03 |
Check Text ( C-50273r768185_chk ) |
---|
Log on to the HYCU Web UI and review the Events menu and Email Notifications to verify that all appropriate/relevant audit failure events are included in the "Category" drop-down menu. If these events are not shown (reference a recent event capturing a login to HYCU for validation), this is a finding. |
Fix Text (F-50227r768186_fix) |
---|
Log on to the HYCU Web UI and go to the "Events" menu and open "Email Notifications". Ensure that all the appropriate/relevant categories are selected and that the "Status" includes failures. Add a "Subject" for the Email Notifications and email address for necessary auditors or HYCU administrators. |