GEN006560 - The system vulnerability assessment tool, host-based intrusion detection tool, and file integrity tool must notify the SA and the IAO of a security breach or a suspected security breach.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Timely notifications of potential security compromises minimize the potential damage.

Minimally, the system must log these events and the SA and the IAO will receive the notifications during the daily system log review. If feasible, active alerting (such as email or paging) should be employed consistent with the site's established operations management systems and procedures.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the security tools on the system to notify the IAO and SA when any security issues are detected.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R2_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, CCI|CCI-001266, Rule-ID|SV-220115r603266_rule, STIG-ID|GEN006560, STIG-Legacy|SV-41530, STIG-Legacy|V-12028, Vuln-ID|V-220115

Plugin: Unix

Control ID: e21915eccb7786dadd17b999fb2ef78cc96a499f665e6bd81428d280b5703257