CCI-000154
Provide the capability to centrally review and analyze audit records from multiple components within the system.
7 rules found Severity: Medium

2 rules found Severity: Medium

The host operating systems auditing policies for the Docker Engine - Enterprise component of Docker Enterprise must be set.
1 rule found Severity: Medium

1 rule found Severity: Medium

4 rules found Severity: Medium

Nutanix AOS must provide the capability to centrally review and analyze audit records from multiple components within the system.
1 rule found Severity: Medium

1 rule found Severity: Medium

Tanium must provide the capability to centrally review and analyze audit records from multiple components within the system.
1 rule found Severity: Medium

The Tanium application must be configured to send audit records from multiple components within the system to a central location for review and analysis of audit records.
2 rules found Severity: Medium

The MDM Agent must be configured to enable the following function: [selection: read audit logs of the MD]. This requirement is inherently met if the function is automatically implemented during MDM Agent install/device enrollment.
1 rule found Severity: Medium

The Ubuntu operating system must produce audit records and reports containing information to establish when, where, what type, the source, and the outcome for all DoD-defined auditable events and actions in near real time.
2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

SLEM 5 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
1 rule found Severity: Medium

The SMS and TPS must provide log information in a format that can be extracted and used by centralized analysis tools.
1 rule found Severity: Medium

The Tanium application must be configured to send audit records from multiple components within the system to a central location for review and analysis.
1 rule found Severity: Medium

TOSS audit records must contain information to establish what type of events occurred, when the events occurred, the source of events, where events occurred, and the outcome of events.
1 rule found Severity: Medium

1 rule found Severity: Medium

The NixOS audit records must be off-loaded onto a different system or storage media from the system being audited.
1 rule found Severity: Medium

1 rule found Severity: Medium

An Apache web server that is part of a web server cluster must route all remote management through a centrally managed access control point.
1 rule found Severity: Medium

The application must provide centralized management and configuration of the content to be captured in audit records generated by all application components.
1 rule found Severity: Medium

The application must provide the capability to centrally review and analyze audit records from multiple components within the system.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must produce audit records and reports containing information to establish when, where, what type, the source, and the outcome for all DOD-defined auditable events and actions in near real time.
1 rule found Severity: Medium

The Central Log Server must be configured to perform analysis of log records across multiple devices and hosts in the enclave that can be reviewed by authorized individuals.
1 rule found Severity: Low

The container platform components must provide the ability to send audit logs to a central enterprise repository for review and analysis.
1 rule found Severity: Medium

1 rule found Severity: Medium

The operating system must provide the capability to centrally review and analyze audit records from multiple components within the system.
1 rule found Severity: Medium

The IDPS must provide log information in a format that can be extracted and used by centralized analysis tools.
1 rule found Severity: Medium

The Mainframe Product must provide the capability to centrally review and analyze audit records from multiple components within the system.
1 rule found Severity: Medium

2 rules found Severity: Medium

OL 8 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
1 rule found Severity: Medium

1 rule found Severity: Medium

OpenShift components must provide the ability to send audit logs to a central enterprise repository for review and analysis.
1 rule found Severity: Medium

1 rule found Severity: Medium

SUSE operating system audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
2 rules found Severity: Medium

The VMM must support the capability to centrally review and analyze audit records from multiple components within the system.
1 rule found Severity: Medium

Rancher MCM must use a centralized user management solution to support account management functions. For accounts using password authentication, the container platform must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.
1 rule found Severity: High
