Logs of web server access and errors must be established and maintained
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-2250
WG240 A22
SV-33025r1_rule
Medium
Description
A major tool in exploring the web site use, attempted use, unusual conditions, and problems are reported in the access and error logs. In the event of a security incident, these logs can provide the SA and the web manager with valuable information. Without these log files, SAs and web managers are seriously hindered in their efforts to respond appropriately to suspicious or criminal actions targeted at the web site.