800-53|AU-5(1)

Title

AUDIT STORAGE CAPACITY

Description

The information system provides a warning to [Assignment: organization-defined personnel, roles, and/or locations] within [Assignment: organization-defined time period] when allocated audit record storage volume reaches [Assignment: organization-defined percentage] of repository maximum audit record storage capacity.

Supplemental

Organizations may have multiple audit data storage repositories distributed across multiple information system components, with each repository having different storage volume capacities.

Reference Item Details

Category: AUDIT AND ACCOUNTABILITY

Parent Title: RESPONSE TO AUDIT PROCESSING FAILURES

Family: AUDIT AND ACCOUNTABILITY

Baseline Impact: HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.14 O19C-00-005900OracleDBCIS Oracle Database 19c STIG v1.1.0 CAT II OracleDB
1.26 SOL-11.1-010370UnixCIS Solaris 11 SPARC STIG v1.0.0 CAT II
1.26 SOL-11.1-010370UnixCIS Solaris 11 X86 STIG v1.0.0 CAT II
1.45 PHTN-40-000112UnixCIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT III
1.46 SQLI-22-011000MS_SQLDBCIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT II MS_SQLDB
1.48 APPL-14-001030UnixCIS Apple macOS 14 Sonoma STIG v1.0.0 CAT II
1.48 APPL-26-001030UnixCIS Apple macOS 26 Tahoe STIG v1.0.0 CAT II
1.49 APPL-15-001030UnixCIS Apple macOS 15 Sequoia STIG v1.0.0 CAT II
1.61 MADB-10-007400UnixCIS MariaDB Enterprise 10.x STIG v1.1.0 CAT II Unix
1.78 AZLX-23-002035UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.79 AZLX-23-002040UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.80 AZLX-23-002045UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.81 AZLX-23-002050UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.82 AZLX-23-002055UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.125 UBTU-22-653040UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT III
1.156 OL09-00-000825UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.157 SLES-15-030700UnixCIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT II
1.164 OL09-00-000865UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.165 OL09-00-000870UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.166 OL09-00-000875UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.168 OL09-00-000885UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.174 RHEL-10-500040UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.175 UBTU-24-900960UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT III
1.177 RHEL-10-500105UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.178 RHEL-10-500110UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.182 RHEL-10-500205UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.183 RHEL-10-500210UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.282 OL08-00-030730UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.283 OL08-00-030731UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.372 RHEL-09-653035UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.373 RHEL-09-653040UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.374 RHEL-09-653045UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.375 RHEL-09-653050UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.379 RHEL-09-653070UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.412 ALMA-09-053260UnixCIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II
1.413 ALMA-09-053370UnixCIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II
1.414 ALMA-09-053480UnixCIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II
1.415 ALMA-09-053590UnixCIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II
3.092 - The system must generate an audit event when the audit log reaches a percentage of full threshold.WindowsDISA Windows Vista STIG v6r41
4.1.1.2 Ensure system is disabled when audit logs are full - 'admin_space_left_action'UnixCIS Ubuntu Linux 14.04 LTS Workstation L2 v2.1.0
4.1.1.2 Ensure system is disabled when audit logs are full - 'admin_space_left_action'UnixCIS Amazon Linux v2.1.0 L2
4.1.1.2 Ensure system is disabled when audit logs are full - 'admin_space_left_action'UnixCIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0
4.1.1.2 Ensure system is disabled when audit logs are full - 'space_left_action is configured'UnixCIS Amazon Linux v2.1.0 L2
4.1.1.2 Ensure system is disabled when audit logs are full - 'space_left_action'UnixCIS Ubuntu Linux 14.04 LTS Workstation L2 v2.1.0
4.1.1.2 Ensure system is disabled when audit logs are full - 'space_left_action'UnixCIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0
4.1.2.4 Ensure system notification is sent out when volume is 75% fullUnixCIS Amazon Linux 2 STIG v2.0.1 STIG
4.1.2.4 Ensure system notification is sent out when volume is 75% full - SA and Information System Security Officer ISSO, at a minimum, when allocated audit record storage volume reaches 75% of the repository maximum audit record storage capacity.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
4.1.2.5 Ensure system is disabled when audit logs are fullUnixCIS Amazon Linux 2 STIG v2.0.1 STIG
4.1.2.5 Ensure system is disabled when audit logs are fullUnixCIS Amazon Linux 2 STIG v2.0.1 L2 Server
4.1.2.5 Ensure system is disabled when audit logs are full - at a minimum via email when the threshold for the repository maximum audit record storage capacity is reached.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG