STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288206

CAT II (Medium)

The application must produce audit records containing descriptions of the audit events.

Rule ID

SV-288206r1252756_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-000130

Discussion

Without information about the outcome of events, security personnel cannot make an accurate assessment as to whether an attack was successful or if changes were made to the security state of the system. Event outcomes can include indicators of event success or failure and event-specific results (e.g., event descriptions such as what type of event occurred). As such, they also provide a means to measure the impact of an event and help authorized personnel to determine the appropriate response. Organizations log system accesses associated with applying configuration changes to ensure that configuration change control is implemented and to support after-the-fact actions should organizations discover any unauthorized changes.

Check Content

Review the application documentation and deployed configuration to determine whether the application's auditing mechanism produces audit records containing descriptions of the audit events.

If the application's auditing mechanism does not produce audit records containing descriptions of the audit events, this is a finding.

Fix Text

Navigate to the auditing function configuration within the application.

Configure the application's auditing mechanism to produce audit records containing descriptions of the audit events.