SV-222492r508029_rule
V-222492
SRG-APP-000366
APSC-DV-001180
CAT II
10
Design or configure the application to provide an immediate audit review capability or utilize a centralized utility designed for the purpose of on-demand log management and reporting.
Review the application documentation and interview the application administrator for details regarding audit reduction (log record event filtering).
Access the application with user rights sufficient to read and filter audit records.
Navigate the application user interface and select the application functionality that provides access and interface to audit records and audit reporting.
If the application uses a centralized logging solution that provides immediate, customizable audit review and analysis functions, the requirement is not applicable.
Create an event report. Report data can be based on date ranges, times or events, or other criteria that could be used in an investigation. Use of data from previous checks for audit reduction is encouraged.
Review the report and ensure the data in the report coincides with event filters used to create the report.
If the application does not provide an immediate, ad-hoc audit review and analysis capability, this is a finding.
V-222492
False
APSC-DV-001180
Review the application documentation and interview the application administrator for details regarding audit reduction (log record event filtering).
Access the application with user rights sufficient to read and filter audit records.
Navigate the application user interface and select the application functionality that provides access and interface to audit records and audit reporting.
If the application uses a centralized logging solution that provides immediate, customizable audit review and analysis functions, the requirement is not applicable.
Create an event report. Report data can be based on date ranges, times or events, or other criteria that could be used in an investigation. Use of data from previous checks for audit reduction is encouraged.
Review the report and ensure the data in the report coincides with event filters used to create the report.
If the application does not provide an immediate, ad-hoc audit review and analysis capability, this is a finding.
M
4093