Innoslate must off-load audit records onto a different system or media than the system being audited.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-254095
SPEC-IN-000720
SV-254095r845261_rule
Medium
Description
Information stored in one location is vulnerable to accidental or incidental deletion or alteration.
Offloading is a common process in information systems with limited audit storage capacity.
1. Access the logging.properties file in the logs directory of the Innoslate files.
2. Verify the ____.apache.juli.AsyncFileHandler.directory field is set to a directory on a different system. Otherwise, this is a finding.
Fix Text (F-57531r845260_fix)
1. Access the logging.properties file in the logs directory of the Innoslate files.
2. Set the ____.apache.juli.AsyncFileHandler.directory fields to the directory or directories required.
3. Save.
4. Restart the service.