Skip to content

The application server must, at a minimum, transfer the logs of interconnected systems in real time, and transfer the logs of standalone systems weekly.

An XCCDF Rule

Description

Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Protecting log data is important during a forensic investigation to ensure investigators can track and understand what may have occurred. Off-loading should be set up as a scheduled task but can be configured to be run manually, if other processes during the off-loading are manual. Off-loading is a common process in information systems with limited log storage capacity.

ID
SV-204833r961860_rule
Version
SRG-APP-000515-AS-000203
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the application server to off-load interconnected systems in real time and standalone systems weekly.