Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-32961 | SRG-OS-000045-MOS-000020 | SV-43359r1_rule | Medium |
Description |
---|
Operating system auditing capability is critical for accurate forensic analysis. Audit record content that may be necessary to satisfy the requirement of this control includes timestamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, file names involved, and access control or flow control rules invoked. Care must be taken to evaluate that the audit records being produced do not exceed the storage capacity. Alerting the mobile device management server when audit log size thresholds are exceeded helps appropriate personnel to respond to heavy activity in a timely manner. Failure to alert increases the probability that an adversary's actions will go undetected. |
STIG | Date |
---|---|
Mobile Operating System Security Requirements Guide | 2013-04-12 |
Check Text ( C-41262r1_chk ) |
---|
Verify the auditing system can alert the mobile device management server when the audit log size reaches an organization defined critical percentage of capacity and full capacity. If the auditing system cannot alert the mobile device management server when the audit log size reaches an organization defined critical percentage of capacity and full capacity or is not configured to do so, this is a finding. |
Fix Text (F-36876r1_fix) |
---|
Configure the mobile operating system to send alerts to the mobile device management server when the audit log size reaches an organization defined critical percentage of capacity and full capacity. |