Skip to content

Log file access must be restricted to System Administrators, Web Administrators or Auditors.

An XCCDF Rule

Description

A major tool in exploring the web site use, attempted use, unusual conditions and problems are the access and error logs. In the event of a security incident, these logs can provide the SA and Web Manager with valuable information. To ensure the integrity of the log files and protect the SA and Web Manager from a conflict of interest related to the maintenance of these files, only the members of the Auditors group will be granted permissions to move, copy and delete these files in the course of their duties related to the archiving of these files.

Property Value
Responsibility System Administrator

ID
SV-33135r1_rule
Version
WG250 W22
Severity
Medium
Updated

Remediation Templates

A Manual Procedure

Remove the unauthorized permissions from the applicable accounts.