The ISSO must ensure application audit trails are retained for at least 1 year for applications without SAMI data, and 5 years for applications including SAMI data.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-222621 | APSC-DV-002900 | SV-222621r961863_rule | CCI-000167 | medium |
| Description | ||||
| Log files are a requirement to trace intruder activity or to audit user activity. | ||||
| STIG | Date | |||
| Application Security and Development Security Technical Implementation Guide | 2025-02-12 | |||
Related Frameworks
4 paths across 3 frameworks
Related Frameworks
NIST 800-531 mapping
AU-11
1.00
- DISA · 6 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1712 mappings
3.3.1
1.00
- DISA · 6 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.3.2
1.00
- DISA · 6 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000167
1.00
- DISA · 6 · disa_xccdf · related
Details
Check Text (C-222621r961863_chk)
Verify a process is in place to retain application audit log files for one year and five years for SAMI data.
If audit logs have not been retained for one year or five years for SAMI data, this is a finding.
Fix Text (F-24280r493772_fix)
Retain application audit log files for one year and five years for SAMI data.