The ISSO must ensure application audit trails are retained for at least 1 year for applications without SAMI data, and 5 years for applications including SAMI data.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-222621APSC-DV-002900SV-222621r961863_ruleCCI-000167medium
Description
Log files are a requirement to trace intruder activity or to audit user activity.
STIGDate
Application Security and Development Security Technical Implementation Guide2025-02-12

Related Frameworks

4 paths across 3 frameworks
NIST 800-531 mapping
AU-11
1.00
  • DISA · 6 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1712 mappings
3.3.1
1.00
  • DISA · 6 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.3.2
1.00
  • DISA · 6 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000167
1.00
  • DISA · 6 · disa_xccdf · related

Details

Check Text (C-222621r961863_chk)

Verify a process is in place to retain application audit log files for one year and five years for SAMI data. If audit logs have not been retained for one year or five years for SAMI data, this is a finding.

Fix Text (F-24280r493772_fix)

Retain application audit log files for one year and five years for SAMI data.