UCF STIG Viewer Logo

The operating system must provide the capability to automatically process audit records for events of interest based upon selectable, event criteria.


Overview

Finding ID Version Rule ID IA Controls Severity
V-29072 SRG-OS-000054 SV-37063r1_rule Medium
Description
Audit reduction is used to reduce the volume of audit records in order to facilitate manual review. Before a security review information systems and/or applications with an audit reduction capability may remove many audit records known to have little security significance. This is generally accomplished by removing records generated by specified classes of events, such as records generated by nightly backups. An audit reduction capability provides support for near real-time audit review and analysis based on policy requirements regarding what must be audited on the system and after-the-fact investigations of security incidents. Audit reduction and reporting tools do not alter original audit records.
STIG Date
Operating System Security Requirements Guide 2013-03-28

Details

Check Text ( None )
None
Fix Text (None)
None