STIGhubSTIGhub
STIGsSearchCompareAbout

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Container Platform Security Requirements Guide

V-233169

CAT II (Medium)

Audit records must be stored at a secondary location.

Rule ID

SV-233169r961395_rule

STIG

Container Platform Security Requirements Guide

Version

V2R4

CCIs

CCI-001851

Discussion

Auditable events are used in the investigation of incidents and must be protected from being deleted or altered. Often, events that took place in the past must be viewed to understand the entire incident. For the purposes of audit event protection and recall, audit events are often off-loaded to an external storage location. The container platform must provide a mechanism to assist in the off-loading of the audit data or at a minimum, must not hinder an external process used for audit event off-loading.

Check Content

Verify the log records are being off-loaded to a separate system or transferred from the container platform storage location to a storage location other than the container platform itself. 

The information system may demonstrate this capability using a log management application, system configuration, or other means. 

If logs are not being off-loaded, this is a finding.

Fix Text

Configure the container platform to off-load the logs to a remote log or management server.