The HYCU virtual appliance must generate an immediate real-time alert of all audit failure events requiring real-time alerts.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-268254HYCU-ND-000430SV-268254r1038704_ruleCCI-001858medium
Description
It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without a real-time alert, security personnel may be unaware of an impending failure of the audit capability and system operation may be adversely affected. Satisfies: SRG-APP-000360-NDM-000295, SRG-APP-000795-NDM-000130
STIGDate
HYCU Protege Security Technical Implementation Guide2024-10-29

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
  • DISA · 1 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-001858
1.00
  • DISA · 1 · disa_xccdf · related

Details

Check Text (C-268254r1038704_chk)

Log in to the HYCU Web UI and review the "Events" menu and "Email Notifications" to verify that all appropriate/relevant audit failure events are included in the "Category" drop-down menu. If these events are not shown (reference a recent event capturing a login to HYCU for validation), this is a finding.

Fix Text (F-72178r1038703_fix)

Log in to the HYCU Web UI and go to the "Events" menu and open "Email Notifications". Ensure that all the appropriate/relevant categories are selected and that the "Status" includes failures. Add a "Subject" for the "Email Notifications" and email address for necessary auditors or HYCU administrators.