The network device must off-load audit records onto a different system or media than the system being audited.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-202127
SRG-APP-000515-NDM-000325
SV-202127r961860_rule
Medium
Description
Information stored in one location is vulnerable to accidental or incidental deletion or alteration.
Off-loading is a common process in information systems with limited audit storage capacity.
Check the network device configuration to determine if the device off-loads audit records onto a different system or media than the system being audited.
If the device does not off-load audit records onto a different system or media, this is a finding.
Fix Text (F-2254r382062_fix)
Configure the network device to off-load audit records onto a different system or media than the system being audited.