UCF STIG Viewer Logo

The network device must protect audit log information from unauthorized modification.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000099-NDM-000068 SRG-NET-000099-NDM-000068 SRG-NET-000099-NDM-000068_rule Low
Description
Logging the actions of specific events provides a means to investigate an attack, recognize resource utilization or capacity thresholds, or to simply identify an improperly configured system. Audit and event log data must be protected from unauthorized access, including from legitimate administrators who do not have a need for this type of access. Without this protection, a compromise or loss of log data needed for incident analysis or risk assessment could result.
STIG Date
Network Device Management Security Requirements Guide 2013-07-30

Details

Check Text ( C-SRG-NET-000099-NDM-000068_chk )
Verify a security policy for the audit logs is in place which allows only system administrators with the proper authorization to modify the network device audit log.

If audit logs are not protected from unauthorized modification, this is a finding.
Fix Text (F-SRG-NET-000099-NDM-000068_fix)
Create and implement an access control security policy to prevent unauthorized modification of the audit logs on the network device.