The Apache web server must use a logging mechanism that is configured to alert the Information System Security Officer (ISSO) and System Administrator (SA) in the event of a processing failure.
DISA Rule
SV-214234r612240_rule
Vulnerability Number
V-214234
Group Title
SRG-APP-000108-WSR-000166
Rule Version
AS24-U1-000160
Severity
CAT II
CCI(s)
- CCI-000139 - The information system alerts designated organization-defined personnel or roles in the event of an audit processing failure.
- CCI-001855 - The information system provides a warning to organization-defined personnel, roles, and/or locations within an organization-defined time period when allocated audit record storage volume reaches an organization-defined percentage of repository maximum audit record storage capacity.
Weight
10
Fix Recommendation
Work with the SIEM administrator to configure an alert when no audit data is received from Apache based on the defined schedule of connections.
Check Contents
Work with the SIEM administrator to determine if an alert is configured when audit data is no longer received as expected.
If there is no alert configured, this is a finding.
Vulnerability Number
V-214234
Documentable
False
Rule Version
AS24-U1-000160
Severity Override Guidance
Work with the SIEM administrator to determine if an alert is configured when audit data is no longer received as expected.
If there is no alert configured, this is a finding.
Check Content Reference
M
Target Key
3996
Comments