SV-222484r508029_rule
V-222484
SRG-APP-000360
APSC-DV-001100
CAT II
10
Configure the log alerts to send an alarm when the audit system is in danger of failing or has failed.
Configure the log alerts to be immediately sent to the application admin/SA and ISSO.
Review system documentation and interview application administrator for details regarding application security categorization and logging configuration.
If the application utilizes a centralized logging system that provides the real-time alarms, this requirement is not applicable.
Review application log alert configuration.
Identify audit failure events and associated alarming configuration.
If the application is categorized as having a moderate or high impact and is not configured to provide a real-time alert that indicates the audit system has failed or is failing, this is a finding.
V-222484
False
APSC-DV-001100
Review system documentation and interview application administrator for details regarding application security categorization and logging configuration.
If the application utilizes a centralized logging system that provides the real-time alarms, this requirement is not applicable.
Review application log alert configuration.
Identify audit failure events and associated alarming configuration.
If the application is categorized as having a moderate or high impact and is not configured to provide a real-time alert that indicates the audit system has failed or is failing, this is a finding.
M
4093