UCF STIG Viewer Logo

Audit data must be reviewed on a regular basis.


Overview

Finding ID Version Rule ID IA Controls Severity
WN12-AU-000200 WN12-AU-000200 WN12-AU-000200_rule Medium
Description
To be of value, audit logs from critical systems must be reviewed on a regular basis. Critical systems should be reviewed on a daily basis to identify security breaches and potential weaknesses in the security structure. This can be done with the use of monitoring software or other utilities for this purpose.
STIG Date
Microsoft Windows Server 2012 Member Server Security Technical Implementation Guide 2013-07-25

Details

Check Text ( C-WN12-AU-000200_chk )
Determine whether the organization has a policy that requires the review of audit logs on a predetermined schedule and that the policy has been implemented. If audit logs are not reviewed on a regular basis, this is a finding.
Fix Text (F-WN12-AU-000200_fix)
Establish a site policy that defines a schedule for the review of audit logs. Review audit logs as scheduled.