Windows Server 2025 must, at a minimum, off-load audit records of interconnected systems in real time and off-load stand-alone or nondomain-joined systems weekly.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-278042 | WN25-AU-000020 | SV-278042r1182270_rule | CCI-001851 | medium |
| Description | ||||
| Protection of log data includes ensuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration. | ||||
| STIG | Date | |||
| Microsoft Windows Server 2025 Security Technical Implementation Guide | 2026-02-20 | |||
Details
Check Text (C-278042r1182270_chk)
Verify the audit records, at a minimum, are off-loaded for interconnected systems in real time and off-loaded for stand-alone or nondomain-joined systems weekly.
If they are not, this is a finding.
Fix Text (F-82477r1182269_fix)
Configure the system to, at a minimum, off-load audit records of interconnected systems in real time and off-load stand-alone or nondomain-joined systems weekly.