CCI-000139
Alert organization-defined personnel or roles within an organization-defined time period in the event of an audit logging process failure.
31 rules found Severity: Medium

The A10 Networks ADC must send an alert to, at a minimum, the ISSO and SCA when connectivity to the Syslog servers is lost.
1 rule found Severity: Low

The A10 Networks ADC must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Low

Docker Enterprise must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Low

CounterACT must send an alert to, at a minimum, the ISSO and SCA when an audit processing failure occurs.
1 rule found Severity: Medium

SNMP must be changed from default settings and must be configured on the storage system to provide alerts of critical events that impact system security.
1 rule found Severity: Medium

The DataPower Gateway must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

The DataPower Gateway must send an alert to, at a minimum, the ISSO and SCA when an audit processing failure occurs.
1 rule found Severity: Medium

The MQ Appliance messaging server must alert the SA and ISSO, at a minimum, in the event of a log processing failure.
1 rule found Severity: Medium

The MQ Appliance network device must alert the Information System Security Officer (ISSO) and System Administrator (SA) (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

The WebSphere Application Server must alert the SA and ISSO, at a minimum, in the event of a log processing failure.
1 rule found Severity: Low

1 rule found Severity: Medium

The Ivanti MobileIron Core server must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

The ISEC7 EMM Suite must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

The Sentry must send an alert to, at a minimum, the ISSO and SCA when an audit processing failure occurs.
2 rules found Severity: Low

1 rule found Severity: Medium

Oracle WebLogic must provide a real-time alert when organization-defined audit failure events occur.
1 rule found Severity: Low

Oracle WebLogic must alert designated individual organizational officials in the event of an audit processing failure.
1 rule found Severity: Low

Oracle WebLogic must provide system notifications to a list of response personnel who are identified by name and/or role.
1 rule found Severity: Medium

Riverbed Optimization System (RiOS) must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

The SEL-2740S must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

2 rules found Severity: Medium

The Tanium application must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
2 rules found Severity: Medium

The Tanium operating system (TanOS) must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
2 rules found Severity: Medium

The Ubuntu operating system must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
2 rules found Severity: Medium

The Red Hat Enterprise Linux operating system must shut down upon audit processing failure, unless availability is an overriding concern. If availability is a concern, the system must alert the designated staff (System Administrator [SA] and Information System Security Officer [ISSO] at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

The BIG-IP appliance must be configured to alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Low

The application server must alert the system administrator (SA) and information system security offer (ISSO), at a minimum, in the event of a log processing failure.
1 rule found Severity: Medium

The Cisco ISE must generate a critical alert to be sent to the ISSO and SA (at a minimum) if it is unable to communicate with the central event log. This is required for compliance with C2C Step 1.
1 rule found Severity: Medium

The Enterprise Voice, Video, and Messaging Session Manager must alert the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of a session (call) record system failure.
1 rule found Severity: Medium

SSMC web server must use a logging mechanism that is configured to alert the ISSO and SA in the event of a processing failure.
1 rule found Severity: Medium

The HPE 3PAR OS must be configured to send SNMP alerts to alert in the event of an audit processing failure.
1 rule found Severity: Medium

1 rule found Severity: Medium

The ISEC7 SPHERE must alert the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

The Ivanti EPMM server must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Oracle Linux operating system must shut down upon audit processing failure, unless availability is an overriding concern. If availability is a concern, the system must alert the designated staff (System Administrator [SA] and Information System Security Officer [ISSO] at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

Automation Controller must use external log providers that can collect user activity logs in independent, protected repositories to prevent modification or repudiation.
1 rule found Severity: Medium

The information system security officer (ISSO) and system administrator (SA), at a minimum, must have mail aliases to be notified of a SLEM 5 audit processing failure.
1 rule found Severity: Medium

The information system security officer (ISSO) and system administrator (SA), at a minimum, must be alerted of a SLEM 5 audit processing failure event.
1 rule found Severity: Medium

The Tanium application must alert the information system security officer and system administrator (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

1 rule found Severity: Medium

The web server must use a logging mechanism that is configured to alert the ISSO and SA in the event of a processing failure.
1 rule found Severity: Medium

NixOS must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent utilization.
1 rule found Severity: Medium

NixOS must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 90 percent utilization.
1 rule found Severity: Medium

NixOS must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
1 rule found Severity: Medium

NixOS must take action when allocated audit record storage volume reaches 90 percent of the repository maximum audit record storage capacity.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Apache web server must use a logging mechanism that is configured to alert the Information System Security Officer (ISSO) and System Administrator (SA) in the event of a processing failure.
1 rule found Severity: Medium

The Apache web server must use a logging mechanism that is configured to alert the (ISSO) and System Administrator (SA) in the event of a processing failure.
1 rule found Severity: Medium

The ALG must send an alert to, at a minimum, the ISSO and SCA when an audit processing failure occurs.
1 rule found Severity: Medium

The application server must alert the SA and ISSO, at a minimum, in the event of a log processing failure.
1 rule found Severity: Medium

The application must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must alert the information system security officer (ISSO) and system administrator (SA) in the event of an audit processing failure.
1 rule found Severity: Low

AlmaLinux OS 9 System Administrator (SA) and/or information system security officer (ISSO) (at a minimum) must be alerted of an audit processing failure event.
1 rule found Severity: Medium

AlmaLinux OS 9 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

1 rule found Severity: Medium

Forescout must configure TCP for the syslog protocol to allow for detection by the central event server if communications is lost. This is required for compliance with C2C Step 1.
1 rule found Severity: Medium

The operating system must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

The Mainframe Product must alert the system administrator (SA) and information system security officer (ISSO) (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

The Juniper SRX Services Gateway must generate an alert message to the management console and generate a log event record that can be forwarded to the ISSO and designated system administrators when the local accounts (i.e., the account of last resort or root account) are modified.
1 rule found Severity: Medium

The OL 8 System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) must be alerted of an audit processing failure event.
1 rule found Severity: Medium

The OL 8 Information System Security Officer (ISSO) and System Administrator (SA) (at a minimum) must have mail aliases to be notified of an audit processing failure.
1 rule found Severity: Medium

The RHEL 8 System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) must be alerted of an audit processing failure event.
1 rule found Severity: Medium

The RHEL 8 Information System Security Officer (ISSO) and System Administrator (SA) (at a minimum) must have mail aliases to be notified of an audit processing failure.
1 rule found Severity: Medium

1 rule found Severity: Medium

RHEL 9 System Administrator (SA) and/or information system security officer (ISSO) (at a minimum) must be alerted of an audit processing failure event.
1 rule found Severity: Medium

RHEL 9 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.
1 rule found Severity: Medium

The Information System Security Officer (ISSO) and System Administrator (SA), at a minimum, must be alerted of a SUSE operating system audit processing failure event.
2 rules found Severity: Medium

The Information System Security Officer (ISSO) and System Administrator (SA), at a minimum, must have mail aliases to be notified of a SUSE operating system audit processing failure.
2 rules found Severity: Medium

1 rule found Severity: Medium

The operating system must alert designated organizational officials in the event of an audit processing failure.
2 rules found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium
