Rule ID
SV-237938r851946_rule
Version
V2R2
CCIs
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity.
If there is no documented process for audit offload, this is a finding. Examine the documented user process for audit record offload. If the procedure does not offload to a different system or media, this is a finding.
Develop a user written procedure to offload audit records to a different system or media.