The application server must, at a minimum, transfer the logs of interconnected systems in real time, and transfer the logs of standalone systems weekly.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-204833
SRG-APP-000515-AS-000203
SV-204833r961860_rule
Medium
Description
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Protecting log data is important during a forensic investigation to ensure investigators can track and understand what may have occurred. Off-loading should be set up as a scheduled task but can be configured to be run manually, if other processes during the off-loading are manual.
Off-loading is a common process in information systems with limited log storage capacity.