SV-95863r1_rule
V-81149
SRG-APP-000360-AU-000130
SRG-APP-000360-AU-000130
CAT III
10
For the host and devices within its scope of coverage, configure the Central Log Server to send an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events such as loss of communications with hosts and devices, or if log records are no longer being received.
Examine the configuration.
Verify the system is configured to send an alert to the SA and ISSO, within seconds or less, when communication is lost with any host or device within the scope of coverage that may indicate an audit failure.
Verify the system is configured to send an alert if hosts and devices stop sending log records to the Central Log Server.
If the Central Log Server is not configured to send a real-time alert to the SA and ISSO (at a minimum) of all audit failure events, this is a finding.
V-81149
False
SRG-APP-000360-AU-000130
Examine the configuration.
Verify the system is configured to send an alert to the SA and ISSO, within seconds or less, when communication is lost with any host or device within the scope of coverage that may indicate an audit failure.
Verify the system is configured to send an alert if hosts and devices stop sending log records to the Central Log Server.
If the Central Log Server is not configured to send a real-time alert to the SA and ISSO (at a minimum) of all audit failure events, this is a finding.
M
3395