CCI-001849
Allocate audit log storage capacity to accommodate organization-defined audit record retention requirements.
The Docker Enterprise max-size and max-file json-file drivers logging options in the daemon.json configuration file must be configured to allocate audit record storage capacity for Universal Control Plane (UCP) and Docker Trusted Registry (DTR) per the requirements set forth by the System Security Plan (SSP).
1 rule found Severity: Medium

The FortiGate device must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

The HP FlexFabric Switch must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

The storage system must allocate audit record storage capacity to store at least one weeks worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

The HYCU server must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

The DataPower Gateway must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

DB2 must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

The WebSphere Application Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements.
1 rule found Severity: Medium

The WebSphere Application Server must allocate audit log record storage capacity in accordance with organization-defined log record storage requirements.
1 rule found Severity: Medium

SQL Server must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
2 rules found Severity: Medium

Nutanix AOS must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

The Tanium SQL Server RDBMS must be configured with sufficient free space to ensure audit logging is not impacted.
2 rules found Severity: Medium

The Tanium application must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
3 rules found Severity: Medium

The macOS system must allocate audit record storage capacity to store at least one week's worth of audit records when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

The Ubuntu operating system must allocate audit record storage capacity to store at least one weeks worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Low

MongoDB must allocate audit record storage capacity in accordance with site audit record storage requirements.
3 rules found Severity: Medium

PostgreSQL must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
3 rules found Severity: Medium

The EDB Postgres Advanced Server must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
2 rules found Severity: Medium

The BIG-IP appliance must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

The macOS system must allocate audit record storage capacity to store at least seven days of audit records when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Low

1 rule found Severity: Medium

The Ubuntu operating system must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Low

The Cisco ASA must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

The Cisco switch must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
3 rules found Severity: Medium

The Cisco router must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
3 rules found Severity: Medium

1 rule found Severity: Medium

The F5 BIG-IP appliance must manage local audit storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Low

SSMC must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

The HPE 3PAR operating system must be configured to allocate audit record storage capacity to store at least one week of audit records, even though all audit records are immediately sent to a centralized audit record storage system (SIEM).
1 rule found Severity: Medium

AIX must allocate audit record storage capacity to store at least one weeks worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

The WebSphere Liberty Server must allocate JVM log record storage capacity in accordance with organization-defined log record storage requirements.
1 rule found Severity: Medium

The ICS must be configured to allocate local audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

The Juniper EX switch must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

MarkLogic Server must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

Azure SQL Database must be able to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

The IIS 10.0 web server must use a logging mechanism configured to allocate log record storage capacity large enough to accommodate the logging requirements of the IIS 10.0 web server.
1 rule found Severity: Medium

The IIS 10.0 website must use a logging mechanism configured to allocate log record storage capacity large enough to accommodate the logging requirements of the IIS 10.0 website.
1 rule found Severity: Medium

3 rules found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

The network device must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

ONTAP must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

The Oracle Linux operating system must use a separate file system for the system audit data path large enough to hold at least one week of audit data.
1 rule found Severity: Low

The MySQL Database Server 8.0 must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

Redis Enterprise DBMS must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

Rancher MCM must allocate audit record storage and generate audit records associated with events, users, and groups.
1 rule found Severity: Medium

Automation Controller must allocate log record storage capacity and shut down by default upon log failure (unless availability is an overriding concern).
1 rule found Severity: Medium

SLEM 5 must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

TOSS must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

The web server must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server.
1 rule found Severity: Medium

NixOS must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
1 rule found Severity: Medium

The Apache web server must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the Apache web server.
2 rules found Severity: Medium

The application server must allocate log record storage capacity in accordance with organization-defined log record storage requirements.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Low

The container platform must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

AlmaLinux OS 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
1 rule found Severity: Low

1 rule found Severity: Low

AlmaLinux OS 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
1 rule found Severity: Medium

The DBMS must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

The HYCU virtual appliance must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

The operating system must allocate audit record storage capacity to store at least one week's worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Low

IBM z/OS SMF collection files (system MANx data sets or LOGSTREAM DASD) must have storage capacity to store at least one weeks worth of audit data.
2 rules found Severity: Medium

IBM z/OS SMF collection files (system MANx datasets or LOGSTREAM DASD) must have storage capacity to store at least one weeks worth of audit data.
1 rule found Severity: Medium

The Juniper router must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

For local log files, the Juniper SRX Services Gateway must allocate log storage capacity in accordance with organization-defined log record storage requirements so that the log files do not grow to a size that causes operational issues.
1 rule found Severity: Medium

The mainframe product must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

MariaDB must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The node that runs Prisma Cloud Compute containers must have sufficient disk space to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
1 rule found Severity: Medium

Red Hat Enterprise Linux CoreOS (RHCOS) must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Low

OL 8 must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

RHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
1 rule found Severity: Low

RHEL 8 must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

RHEL 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
1 rule found Severity: Medium

RHEL 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
1 rule found Severity: Low

The SUSE operating system must allocate audit record storage capacity to store at least one weeks worth of audit records when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

The SUSE operating system must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

The operating system must configure auditing to reduce the likelihood of storage capacity being exceeded.
2 rules found Severity: High

1 rule found Severity: High

The VMM must allocate audit record storage capacity to store at least one weeks worth of audit records when audit records are not immediately sent to a central audit record storage facility.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Lookup Service must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server.
1 rule found Severity: Medium

The ESXi host must allocate audit record storage capacity to store at least one week's worth of audit records.
2 rules found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

The Photon operating system must configure auditd to keep logging in the event max log file size is reached.
1 rule found Severity: Medium

1 rule found Severity: Medium

vSphere UI must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server.
1 rule found Severity: Medium
