SV-221628r508660_rule
V-221628
SRG-APP-000516-AU-000350
SPLK-CL-000320
CAT II
10
Configure Splunk Enterprise, using the reporting and notification tools, to notify the SA and ISSO, at a minimum, when an attack is detected on multiple devices and hosts within its scope of coverage.
Interview the SA to verify that a process exists to notify the SA and ISSO, at a minimum, when an attack is detected on multiple devices and hosts within its scope of coverage.
Interview the ISSO to confirm receipt of this notification.
If a report does not exist, or the ISSO does not confirm receipt of this report, this is a finding.
V-221628
False
SPLK-CL-000320
Interview the SA to verify that a process exists to notify the SA and ISSO, at a minimum, when an attack is detected on multiple devices and hosts within its scope of coverage.
Interview the ISSO to confirm receipt of this notification.
If a report does not exist, or the ISSO does not confirm receipt of this report, this is a finding.
M
4082