WN12-AU-000203-02 - The operating system must, at a minimum, off-load audit records of interconnected systems in real time and off-load standalone systems weekly.

Information

Protection of log data includes assuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the operating system to, at a minimum, off-load audit records of interconnected systems in real time and off-load standalone systems weekly.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_MS_V3R7_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1), CAT|II, CCI|CCI-001851, Rule-ID|SV-225309r877390_rule, STIG-ID|WN12-AU-000203-02, STIG-Legacy|SV-72133, STIG-Legacy|V-57719, Vuln-ID|V-225309

Plugin: Windows

Control ID: 6f9ad0aa79f33ed6a3a4211769d4e6d6a323ef853c73a838cc89110dd838549a