Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
RHEL-06-000459-PNF | RHEL-06-000459-PNF | RHEL-06-000459-PNF_rule | Medium |
Description |
---|
Intrusion-monitoring tools can accumulate a significant amount of sensitive data; examples could include user account information and application data not related to the intrusion monitoring application itself. Intrusion monitoring tools also obtain information that is critical to conducting forensic analysis on attacks that occur within the network. This data may be sensitive in nature. Information obtained by intrusion monitoring applications in the course of evaluating network and system security needs to be protected. While this is an operating system requirement, the data collected may be in different files or locations depending upon the IDS/IPS product being used. |
STIG | Date |
---|---|
Red Hat Enterprise Linux 6 Security Technical Implementation Guide | 2013-02-05 |
Check Text ( C-RHEL-06-000459-PNF_chk ) |
---|
RHEL6 supports this requirement and cannot be configured to be out of compliance. This is a permanent not a finding. |
Fix Text (F-RHEL-06-000459-PNF_fix) |
---|
This requirement is a permanent not a finding. No fix is required. |