EX19-MB-000034 The RBAC role for audit log management must be defined and restricted.

Information

The RBAC role for the audit log management 'Audit Log Role' should be defined in the Organizational or Enterprise Domain Security Plan (EDSP) to define the necessary personnel that are required to handle audit logs for the Microsoft Exchange application.

Group membership should be audited regularly by checking the EDSP regularly and determine who should and should not have group membership.

There are three built-in groups that automatically have membership: Organization Management, Compliance Management, and Records Management.

Solution

Refer to the EDSP on who should have the RBAC role 'Audit Log'. If a custom RBAC role is designated for the Audit Log role, ensure that the custom RBAC role group is populated.

Follow the rule of least privilege.

Otherwise, in an Exchange management shell, run the following:

'Add-RoleGroupMember -Identity 'Records Management' -Member <user>'

Where <user> is the personnel responsible for handling audit logs.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Exchange_2019_Y24M07_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12b., CAT|II, CCI|CCI-000171, Rule-ID|SV-259655r960882_rule, STIG-ID|EX19-MB-000034, Vuln-ID|V-259655

Plugin: Windows

Control ID: 6d8dcf3cc4758ed4ca9a7d36bbbae2b1bfa6cabca3a3823ab0187cd5a8e23c19