DISA STIGS Viewer

The web server must automatically generate audit records of the enforcement actions.

Overview

Finding ID Version Rule ID IA Controls Severity
V-264341 SRG-APP-000805-WSR-000140 SV-264341r984368_rule   Medium
Description
Organizations log system accesses associated with applying configuration changes to ensure that configuration change control is implemented and to support after-the-fact actions should organizations discover any unauthorized changes.
STIG Date
Web Server Security Requirements Guide 2025-02-12

Details

Check Text (C-68254r984366_chk)
Verify the web server is configured to automatically generate audit records of the enforcement actions.

If the web server is not configured to automatically generate audit records of the enforcement actions, this is a finding.
Fix Text (F-68162r984367_fix)
Configure the web server to automatically generate audit records of the enforcement actions.