Rule ID
SV-204995r831372_rule
Version
V2R3
CCIs
CCI-001851
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity. This does not apply to audit logs generated on behalf of the device itself (management).
Verify the ALG off-loads audit records onto a centralized log server. If the ALG does not off-load audit records onto a centralized log server, this is a finding.
Configure the ALG to off-load audit records onto a centralized log server.