The web server must implement the capability to centrally review and analyze audit records from multiple components within the system.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-264339 | SRG-APP-000745-WSR-000120 | SV-264339r984362_rule | CCI-003821 | medium |
| Description | ||||
| Automated mechanisms for centralized reviews and analyses include security information and event management products. | ||||
| STIG | Date | |||
| Web Server Security Requirements Guide | 2025-02-12 | |||
Related Frameworks
2 paths across 2 frameworks
Related Frameworks
NIST 800-531 mapping
AU-6(4)
1.00
- DISA · 4 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-003821
1.00
- DISA · 4 · disa_xccdf · related
Details
Check Text (C-264339r984362_chk)
Verify the web server is configured to implement the capability to centrally review and analyze audit records from multiple components within the system.
If the web server is not configured to implement the capability to centrally review and analyze audit records from multiple components within the system, this is a finding.
Fix Text (F-68160r984361_fix)
Configure the web server to implement the capability to centrally review and analyze audit records from multiple components within the system.