The ISSO must ensure application audit trails are retained for at least 1 year for applications without SAMI data, and 5 years for applications including SAMI data.
DISA Rule
SV-222621r508029_rule
Vulnerability Number
V-222621
Group Title
SRG-APP-000516
Rule Version
APSC-DV-002900
Severity
CAT II
CCI(s)
- CCI-000366 - The organization implements the security configuration settings.
- CCI-000167 - The organization retains audit records for an organization-defined time period to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements.
Weight
10
Fix Recommendation
Retain application audit log files for one year and five years for SAMI data.
Check Contents
Verify a process is in place to retain application audit log files for one year and five years for SAMI data.
If audit logs have not been retained for one year or five years for SAMI data, this is a finding.
Vulnerability Number
V-222621
Documentable
False
Rule Version
APSC-DV-002900
Severity Override Guidance
Verify a process is in place to retain application audit log files for one year and five years for SAMI data.
If audit logs have not been retained for one year or five years for SAMI data, this is a finding.
Check Content Reference
M
Target Key
4093
Comments