800-53|AU-4(1)

Title

TRANSFER TO ALTERNATE STORAGE

Description

The information system off-loads audit records [Assignment: organization-defined frequency] onto a different system or media than the system being audited.

Supplemental

Off-loading is a process designed to preserve the confidentiality and integrity of audit records by moving the records from the primary information system to a secondary or alternate system. It is a common process in information systems with limited audit storage capacity; the audit storage is used only in a transitory fashion until the system can communicate with the secondary or alternate system designated for storing the audit records, at which point the information is transferred.

Reference Item Details

Category: AUDIT AND ACCOUNTABILITY

Parent Title: AUDIT STORAGE CAPACITY

Family: AUDIT AND ACCOUNTABILITY

Audit Items

View all Reference Audit Items

NamePluginAudit Name
4.10 init.ora - 'Establish redundant physically separate locations for redo log files.'UnixCIS v1.1.0 Oracle 11g OS L1
4.11 init.ora - 'Specify redo logging must be successful.'WindowsCIS v1.1.0 Oracle 11g OS Windows Level 1
20.39 Ensure 'Off-load of audit records of interconnected systems in real time and off-load standalone systems weekly'WindowsCIS Microsoft Windows Server 2022 STIG v1.0.0 STIG MS
20.39 Ensure 'Off-load of audit records of interconnected systems in real time and off-load standalone systems weekly'WindowsCIS Microsoft Windows Server 2022 STIG v1.0.0 STIG DC
AIX7-00-002017 - AIX must be configured so that the audit system takes appropriate action when the audit storage volume is full.UnixDISA STIG AIX 7.x v3r1
AIX7-00-002131 - AIX must implement a remote syslog server that is documented using site-defined procedures.UnixDISA STIG AIX 7.x v3r1
AMLS-NM-000400 - The Arista Multilayer Switch must, at a minimum, off-load audit records for interconnected systems in real time - logging hostAristaDISA STIG Arista MLS DCS-7000 Series NDM v1r4
AMLS-NM-000400 - The Arista Multilayer Switch must, at a minimum, off-load audit records for interconnected systems in real time - trap loggingAristaDISA STIG Arista MLS DCS-7000 Series NDM v1r4
ARST-ND-000850 - The Arista network Arista device must be configured to send log data to a central log server for the purpose of forwarding alerts to the administrators and the ISSO.AristaDISA STIG Arista MLS EOS 4.2x NDM v2r1
AS24-U1-000720 - The Apache web server must not impede the ability to write specified log record content to an audit log server.UnixDISA STIG Apache Server 2.4 Unix Server v3r1 Middleware
AS24-U1-000720 - The Apache web server must not impede the ability to write specified log record content to an audit log server.UnixDISA STIG Apache Server 2.4 Unix Server v3r1
AS24-U1-000730 - The Apache web server must be configured to integrate with an organizations security infrastructure.UnixDISA STIG Apache Server 2.4 Unix Server v3r1
AS24-U1-000730 - The Apache web server must be configured to integrate with an organizations security infrastructure.UnixDISA STIG Apache Server 2.4 Unix Server v3r1 Middleware
AS24-W1-000720 - The Apache web server must not impede the ability to write specified log record content to an audit log server.WindowsDISA STIG Apache Server 2.4 Windows Server v3r1
AS24-W1-000720 - The Apache web server must not impede the ability to write specified log record content to an audit log server.WindowsDISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W1-000730 - The Apache web server must be configurable to integrate with an organizations security infrastructure.WindowsDISA STIG Apache Server 2.4 Windows Server v3r1
AS24-W1-000730 - The Apache web server must be configurable to integrate with an organizations security infrastructure.WindowsDISA STIG Apache Server 2.4 Windows Server v2r3
Big Sur - Off-Load Audit RecordsUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Off-Load Audit RecordsUnixNIST macOS Catalina v1.5.0 - All Profiles
CISC-ND-001310 - The Cisco router must be configured to off-load log records onto a different system than the system being audited.CiscoDISA STIG Cisco IOS-XR Router NDM v3r2
CISC-ND-001310 - The Cisco switch must be configured to off-load log records onto a different system than the system being audited.CiscoDISA STIG Cisco NX-OS Switch NDM v3r2
CISC-ND-001450 - The Cisco router must be configured to send log data to at least two syslog servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).CiscoDISA STIG Cisco IOS XE Router NDM v3r2
CISC-ND-001450 - The Cisco router must be configured to send log data to at least two syslog servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).CiscoDISA STIG Cisco IOS-XR Router NDM v3r2
CISC-ND-001450 - The Cisco router must be configured to send log data to at least two syslog servers for the purpose of forwarding alerts to the administrators and the ISSO.CiscoDISA STIG Cisco IOS Router NDM v3r2
CISC-ND-001450 - The Cisco switch must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).CiscoDISA STIG Cisco IOS Switch NDM v3r2
CISC-ND-001450 - The Cisco switch must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).CiscoDISA STIG Cisco IOS XE Switch NDM v3r2
CISC-ND-001450 - The Cisco switch must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).CiscoDISA STIG Cisco NX-OS Switch NDM v3r2
DB2X-00-012600 - DB2 must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.WindowsDISA STIG IBM DB2 v10.5 LUW v2r1 OS Windows
DB2X-00-012600 - DB2 must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.UnixDISA STIG IBM DB2 v10.5 LUW v2r1 OS Linux
Ensure 'syslog hosts' is configured correctlyCisco_FirepowerTenable Cisco Firepower Threat Defense Best Practices Audit
F5BI-DM-000257 - The BIG-IP appliance must be configured to off-load audit records onto a different system or media than the system being audited.F5DISA F5 BIG-IP Device Management STIG v2r3
GEN005450 - The system must use a remote syslog server (loghost) - rsyslog.confUnixDISA STIG for Oracle Linux 5 v2r1
GEN005450 - The system must use a remote syslog server (loghost) - syslog.confUnixDISA STIG for Oracle Linux 5 v2r1
GOOG-09-005505 - The Google Android Pie must be configured to enable audit logging.MDMAirWatch - DISA Google Android 9.x v2r1
GOOG-09-005505 - The Google Android Pie must be configured to enable audit logging.MDMMobileIron - DISA Google Android 9.x v2r1
GOOG-10-005505 - Google Android 10 must be configured to enable audit logging.MDMMobileIron - DISA Google Android 10.x v2r1
GOOG-10-005505 - Google Android 10 must be configured to enable audit logging.MDMAirWatch - DISA Google Android 10.x v2r1
GOOG-11-005505 - Google Android 11 must be configured to enable audit logging.MDMAirWatch - DISA Google Android 11 COPE v2r1
GOOG-11-005505 - Google Android 11 must be configured to enable audit logging.MDMMobileIron - DISA Google Android 11 COBO v2r1
GOOG-11-005505 - Google Android 11 must be configured to enable audit logging.MDMAirWatch - DISA Google Android 11 COBO v2r1
GOOG-11-005505 - Google Android 11 must be configured to enable audit logging.MDMMobileIron - DISA Google Android 11 COPE v2r1
HONW-09-005505 - The Honeywell Mobility Edge Android Pie device must be configured to enable audit logging.MDMAirWatch - DISA Honeywell Android 9.x COPE v1r2
HONW-09-005505 - The Honeywell Mobility Edge Android Pie device must be configured to enable audit logging.MDMAirWatch - DISA Honeywell Android 9.x COBO v1r2
HONW-09-005505 - The Honeywell Mobility Edge Android Pie device must be configured to enable audit logging.MDMMobileIron - DISA Honeywell Android 9.x COBO v1r2
HONW-09-005505 - The Honeywell Mobility Edge Android Pie device must be configured to enable audit logging.MDMMobileIron - DISA Honeywell Android 9.x COPE v1r2
IBM i : Auditing Force Level (QAUDFRCLVL) - '*SYS'AS/400IBM System i Security Reference for V7R1 and V6R1
IBM i : Auditing Force Level (QAUDFRCLVL) - '*SYS'AS/400IBM System i Security Reference for V7R2
IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.WindowsDISA IIS 10.0 Server v2r10
IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.WindowsDISA IIS 10.0 Server v3r2
IISW-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 8.5 web server must be enabled.WindowsDISA IIS 8.5 Server v2r7