Skip to content

The container platform components must provide the ability to send audit logs to a central enterprise repository for review and analysis.

An XCCDF Rule

Description

<VulnDiscussion>The container platform components must send audit events to a central managed audit log repository to provide reporting, analysis, and alert notification. Incident response relies on successful timely, accurate system analysis in order for the organization to identify and respond to possible security events.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-233052r879572_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Configure the container platform components to send audit logs to a central managed audit log repository.