SV-206700r604133_rule
V-206700
SRG-NET-000335
SRG-NET-000335-FW-000017
CAT II
10
Configure the firewall (or another network device) to send an alert via instant message, email, or another authorized method to the SCA, ISSO, and other identified personnel for any log failure event where the filtering functions are unable to write events to the central audit server.
If a network device such as the events, network management, or SNMP server is configured to send an alert when communication is lost with the central audit server, this is not a finding.
Verify the firewall is configured to send an alert via instant message, email, SNMP, or another authorized method to the SCA, ISSO, and other identified personnel when communication is lost with the central audit server.
If the firewall is not configured to send an immediate alert via an approved method when communication is lost with the central audit server, this is a finding.
V-206700
False
SRG-NET-000335-FW-000017
If a network device such as the events, network management, or SNMP server is configured to send an alert when communication is lost with the central audit server, this is not a finding.
Verify the firewall is configured to send an alert via instant message, email, SNMP, or another authorized method to the SCA, ISSO, and other identified personnel when communication is lost with the central audit server.
If the firewall is not configured to send an immediate alert via an approved method when communication is lost with the central audit server, this is a finding.
M
2912