4.5 Periodically review audit settings

Information

It is recommended that the audit settings are periodically reviewed to ensure that a
sufficient amount of audit events are being collected in accordance with internal and
regulatory requirements and that database performance is acceptable.

Rationale:

Regularly reviewing audit configuration represents security best practice.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. Carry out regular reviews of the system-wide and per server audit settings.


Audit:

1. Ensure that there is a record of current and previous system-wide and per server
audit settings that includes change control information.

See Also

https://workbench.cisecurity.org/files/1612