Rule ID
SV-288244r1252851_rule
Version
V1R0.1
DoW mandates the centralization of event logging to allow security personnel to rapidly visualize data from many sources to spot trends and complex attacks on enterprise assets. The Central Log Server Security Requirements Guide (SRG) supports this goal by providing the technical security policies, requirements, and implementation details for applying security concepts to Security Information and Event Management servers (SIEMs), syslog servers, Network Management Systems (NMSs), and other event-based aggregation and monitoring applications that are part of the events logging, notification, monitoring, and analysis functions in the enterprise. The scope of this document includes applications that leverage aggregated audit logs collected from firewalls, routers, servers, applications, and databases to visualize, monitor, notify, and alert based on identified thresholds. Log management includes log collection/aggregation, secure storage, normalization, event analysis, reporting, and notification/alert generation. Current DoW requirements state that the organization must store the primary log records on a log server (e.g., syslog, SIEM, events server) on a different host than the operating system host being audited. This requirement helps ensure that a compromise of the information system being audited does not also result in a compromise of the audit records. DoW also requires centralized management and configuration of the content to be captured in audit records generated by devices and hosts in the enterprise. Thus, there is a requirement for a central log management, analysis, and reporting function that allows management and configuration of log (events) records.
Review the application documentation and deployed configuration to determine whether the application's auditing mechanism off-loads audit records onto a central logging system at least every seven days. If the application's auditing mechanism does not off-load audit records onto a central logging system at least every seven days, this is a finding.
Navigate to the auditing function configuration within the application. Configure the application's auditing mechanism to off-load audit records onto a central logging system at least every seven days.