Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36308 | SRG-APP-115-MDM-261-SRV | SV-47712r1_rule | Low |
Description |
---|
Due to the numerous functions a MDM server implementation processes, log files can become extremely large because of the volume of data. The more processes that are logged, more log data is collected. This can become very difficult to analyze manually; therefore, it is important to process them automatically and tailor the views of the data to only those events of interest based upon selectable criteria. Without the automation of log processing, based upon events of interest to security personnel, log files will not be viewed accurately and actions will not be taken when a significant event occurs on the system because it can be too overwhelming. Significant or meaningful events may be missed due to the sheer volume of data if logs are reviewed manually. |
STIG | Date |
---|---|
Mobile Device Manager Security Requirements Guide | 2013-01-24 |
Check Text ( C-44549r1_chk ) |
---|
Review the configuration settings to determine whether the MDM server audit feature automatically processes audit records for events of interest based upon selectable, event criteria. Review MDM server documentation and audit configuration. If the MDM server does not automatically process audit records for events of interest based upon selectable, event criteria, this is a finding. |
Fix Text (F-40839r1_fix) |
---|
Configure the MDM server to automatically process audit records for events of interest based upon selectable, event criteria audit records to be used by a report generation capability. |