1.58 WN16-AU-000020

Information

Windows Server 2016 must, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly.

GROUP ID:V-224876
RULE ID:SV-224876r959008

Protection of log data includes ensuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the system to, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly.

See Also

https://workbench.cisecurity.org/benchmarks/23093

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1)

Plugin: Windows

Control ID: a3d0c6662d9bd8700438132b0f92675a25a017af0647d8826ece8da63364bde9