WN22-AU-000010 - Windows Server 2022 audit records must be backed up to a different system or media than the system being audited.

Information

Protection of log data includes ensuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Establish and implement a process for backing up log data to another system or media other than the system being audited.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_Server_2022_V1R4_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1), CAT|II, CCI|CCI-001851, Rule-ID|SV-254294r877390_rule, STIG-ID|WN22-AU-000010, Vuln-ID|V-254294

Plugin: Windows

Control ID: e65a7f8226bd2764ca69a805ed6f2ee537d5cda2f666d29f34d301d3ced237db