Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35349 | SRG-APP-000113-MAPP-NA | SV-46636r1_rule | Medium |
Description |
---|
Audit reduction is used to reduce the volume of audit records in order to facilitate manual review. Before a security review information systems and/or applications with an audit reduction capability may remove many audit records known to have little security significance. This is generally accomplished by removing records generated by specified classes of events, such as records generated by nightly backups. Audit reduction does not alter original audit records. An audit reduction capability provides support for near real-time audit review and analysis requirements and after-the-fact investigations of security incidents. Rationale for non-applicability: This control is required in the MDM SRG. Mobile applications can leverage the audit review, analysis, and reporting tools of centralized logging systems. |
STIG | Date |
---|---|
Mobile Application Security Requirements Guide | 2013-01-04 |
Check Text ( C-43717r1_chk ) |
---|
This requirement is NA for the MAPP SRG. |
Fix Text (F-39895r1_fix) |
---|
The requirement is NA. No fix is required. |