STIGQter STIGQter: STIG Summary: MS Exchange 2010 Edge Transport Server STIG Version: 1 Release: 15 Benchmark Date: 26 Apr 2019:

Audit data must be protected against unauthorized access.

DISA Rule

SV-44031r1_rule

Vulnerability Number

V-33611

Group Title

Exch-2-826

Rule Version

Exch-2-826

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Restrict any unauthorized groups or users from accessing the audit logs.

Check Contents

Obtain the Email Domain Security Plan (EDSP) and locate the authorized groups or users that should have access to the audit data.

If any group or user has access to the audit data that is not documented in the EDSP, this is a finding.

Vulnerability Number

V-33611

Documentable

False

Rule Version

Exch-2-826

Severity Override Guidance

Obtain the Email Domain Security Plan (EDSP) and locate the authorized groups or users that should have access to the audit data.

If any group or user has access to the audit data that is not documented in the EDSP, this is a finding.

Check Content Reference

M

Target Key

1995

Comments