SV-95851r1_rule
V-81137
SRG-APP-000353-AU-000050
SRG-APP-000353-AU-000050
CAT III
10
Configure the Central Log Server with the privileges needed to allow the SA and ISSM to change the level and type of log records that are retained in the centralized repository based on any selectable event criteria.
Based on the documented requirements for each application, configure the events server to retain log records based on criticality level, type of event, and/or retention period, at a minimum.
Examine the configuration.
Verify the SA and ISSM have been assigned the privileges needed to allow these roles to change the level and type of log records that are retained in the centralized repository based on any selectable event criteria.
Verify the retention configuration for each host and device is in compliance with the documented organization criteria, including the identified criticality level, event type, and/or retention period.
If the Central Log Server is not configured to allow the SA and ISSM to change the retention of the log records, this is a finding.
If the retention is not in compliance with the organization’s documentation, this is a finding.
V-81137
False
SRG-APP-000353-AU-000050
Examine the configuration.
Verify the SA and ISSM have been assigned the privileges needed to allow these roles to change the level and type of log records that are retained in the centralized repository based on any selectable event criteria.
Verify the retention configuration for each host and device is in compliance with the documented organization criteria, including the identified criticality level, event type, and/or retention period.
If the Central Log Server is not configured to allow the SA and ISSM to change the retention of the log records, this is a finding.
If the retention is not in compliance with the organization’s documentation, this is a finding.
M
3395