The Central Log Server must be configured to generate on-demand audit review and analysis reports.
From Central Log Server Security Requirements Guide
Part of SRG-APP-000366-AU-000220
Associated with:
CCI-001878
SRG-APP-000366-AU-000220_rule
The Central Log Server must be configured to generate on-demand audit review and analysis reports.
Vulnerability discussion
The report generation capability must support on-demand review and analysis to facilitate the organization's ability to generate incident reports as needed to better handle larger-scale or more complex security incidents. Report generation must be capable of generating on-demand (i.e., customizable, ad hoc, and as-needed) reports. On-demand reporting allows personnel to report issues more rapidly to more effectively meet reporting requirements. Collecting log data and aggregating it to present the data in a single, consolidated report achieves this objective. Audit reduction and report generation capabilities do not always reside on the same information system or within the same organizational entities conducting auditing activities. The audit reduction capability can include, for example, modern data mining techniques with advanced data filters to identify anomalous behavior in log records. The report generation capability provided by the information system can generate customizable reports. Time ordering of log records can be a significant issue if the granularity of the timestamp in the record is insufficient.This requirement is specific to applications with report generation capabilities; however, applications need to support on-demand audit review and analysis.
Check content
Examine the configuration. Verify the Central Log Server generates on-demand audit review and analysis reports.
If the Central Log Server is not configured to generate on-demand audit review and analysis reports, this is a finding.
Fix text
Configure the Central Log Server to generate on-demand audit review and analysis reports.
Pro Tips
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer