The Apache web server must use a logging mechanism that is configured to provide a warning to the Information System Security Officer (ISSO) and System Administrator (SA) when allocated record storage volume reaches 75% of maximum log record storage capacity.
DISA Rule
SV-214350r505936_rule
Vulnerability Number
V-214350
Group Title
SRG-APP-000359-WSR-000065
Rule Version
AS24-W1-000740
Severity
CAT II
CCI(s)
- CCI-001855 - The information system provides a warning to organization-defined personnel, roles, and/or locations within an organization-defined time period when allocated audit record storage volume reaches an organization-defined percentage of repository maximum audit record storage capacity.
Weight
10
Fix Recommendation
Work with the SIEM administrator to configure an alert when no audit data is received from Apache based on the defined schedule of connections.
Check Contents
Work with the SIEM administrator to determine if an alert is configured when audit data is no longer received as expected.
If there is no alert configured, this is a finding.
Vulnerability Number
V-214350
Documentable
False
Rule Version
AS24-W1-000740
Severity Override Guidance
Work with the SIEM administrator to determine if an alert is configured when audit data is no longer received as expected.
If there is no alert configured, this is a finding.
Check Content Reference
M
Target Key
3998
Comments