The operating system must, at a minimum, off-load audit data from interconnected systems in real time and off-load audit data from standalone systems weekly.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-203777
SRG-OS-000479-GPOS-00224
SV-203777r959008_rule
Medium
Description
Information stored in one location is vulnerable to accidental or incidental deletion or alteration.
Off-loading is a common process in information systems with limited audit storage capacity.
Verify the operating system, at a minimum, off-loads interconnected systems in real time and off-loads standalone systems weekly. If it does not, this is a finding.
Fix Text (F-3902r375723_fix)
Configure the operating system to, at a minimum, off-load interconnected systems in real time and off-load standalone systems weekly.