Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-240234 | VRAU-LI-000140 | SV-240234r879582_rule | Medium |
Description |
---|
Protection of Lighttpd log data includes assuring log data is not accidentally lost or deleted. Backing up Lighttpd log records to an unrelated system or onto separate media than the system the web server is actually running on helps to assure that, in the event of a catastrophic system failure, the log records will be retained. |
STIG | Date |
---|---|
VMware vRealize Automation 7.x Lighttpd Security Technical Implementation Guide | 2023-09-12 |
Check Text ( C-43467r668005_chk ) |
---|
Obtain supporting documentation from the ISSO. Determine whether log data and records are being backed up to a different system or separate media. If log data and records are not being backed up to a different system or separate media, this is a finding. |
Fix Text (F-43426r667878_fix) |
---|
Backup the log data and records to a different system or separate media. |