Windows Server 2022 audit records must be backed up to a different system or media than the system being audited.
Overview
Finding ID | Version | Rule ID | IA Controls | Severity |
V-254294 | WN22-AU-000010 | SV-254294r958754_rule | Medium |
Description |
Protection of log data includes ensuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration. |
STIG | Date |
Microsoft Windows Server 2022 Security Technical Implementation Guide | 2025-01-14 |
Details
Check Text (C-57779r848696_chk) |
Determine if a process to back up log data to a different system or media than the system being audited has been implemented. If it has not, this is a finding. |
Fix Text (F-57730r848697_fix) |
Establish and implement a process for backing up log data to another system or media other than the system being audited. |