Skip to content

II - Mission Support Classified

Rules and Groups employed by this XCCDF Profile

  • SLEM 5 must offload audit records onto a different system or media from the system being audited.

    Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Offloading is a common process in information systems with limited audit storage capacity.
    Rule Medium Severity
  • SRG-OS-000479-GPOS-00224

    Group
  • Audispd must take appropriate action when SLEM 5 audit storage is full.

    Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Offloading is a common process in information systems with limited audit storage capacity.
    Rule Medium Severity
  • SRG-OS-000057-GPOS-00027

    Group
  • SLEM 5 must protect audit rules from unauthorized modification.

    Without the capability to restrict which roles and individuals can select which events are audited, unauthorized personnel may be able to prevent the auditing of critical events. Misconfigured audi...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules