SV-221214r612603_rule
V-221214
SRG-APP-000120
EX16-ED-000130
CAT II
10
Update the EDSP to reflect the authorized groups or users that should have delete permissions for the audit data.
Restrict any unauthorized groups' or users' delete permissions for the audit logs.
Review the Email Domain Security Plan (EDSP).
Determine the authorized groups or users that should have delete permissions for the audit data.
If any group or user has delete permissions for the audit data that is not documented in the EDSP, this is a finding.
V-221214
False
EX16-ED-000130
Review the Email Domain Security Plan (EDSP).
Determine the authorized groups or users that should have delete permissions for the audit data.
If any group or user has delete permissions for the audit data that is not documented in the EDSP, this is a finding.
M
4079