The application server must, at a minimum, transfer the logs of interconnected systems in real time, and transfer the logs of standalone systems weekly.
An XCCDF Rule
Description
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Protecting log data is important during a forensic investigation to ensure investigators can track and understand what may have occurred. Off-loading should be set up as a scheduled task but can be configured to be run manually, if other processes during the off-loading are manual. Off-loading is a common process in information systems with limited log storage capacity.
- ID
- SV-204833r961860_rule
- Version
- SRG-APP-000515-AS-000203
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the application server to off-load interconnected systems in real time and standalone systems weekly.