UCF STIG Viewer Logo

The mobile operating system must allocate sufficient audit record storage capacity for 24 hours of operation.


Overview

Finding ID Version Rule ID IA Controls Severity
V-32960 SRG-OS-000044-MOS-000019 SV-43358r1_rule Medium
Description
Operating system auditing capability is critical for accurate forensic analysis. Audit record content that may be necessary to satisfy the requirement of this control includes timestamps, source and destination addresses, user/process identifiers, event descriptions, success/fail indications, file names involved, and access control or flow control rules invoked. It is imperative the operating system configured, allocate storage capacity to contain audit records. Without adequate storage for audit records, there is the potential that critical audit records will be lost or overwritten. An adversary may be able to take advantage of lack of audit storage capacity to avoid detection. Allocating sufficient audit record storage capacity for 24 hours allows the device to capture critical events even if it is unable to reach the MDM for a full day, such as when an employee may be temporarily in a remote location. The mobile operating system must be capable of allocating sufficient record storage capacity for mission needs. Make sure that the reserved audit capacity is greater than the log size for the day with the greatest log activity. It is advised that the allocated storage capacity be at least 150% of that needed for the most active day observed. Also use other available information resources (e.g., vendor documentation) to determine appropriate required capability based on industry norms.
STIG Date
Mobile Operating System Security Requirements Guide 2013-07-03

Details

Check Text ( C-41261r1_chk )
Review the mobile operating system configuration for allocating sufficient audit record storage capacity for 24 hours of operation. The logs may need to be ported to another device to parse and measure the entries for each day. If the reserved storage for the audit records is less than indicated by these guidelines, this is a finding.
Fix Text (F-36875r1_fix)
Configure the mobile operating system to allocate sufficient audit record storage capacity for 24 hours of operation.