Rule ID
SV-88055r1_rule
Version
V1R10
CCIs
Protection of log data includes assuring the log data is not accidentally lost or deleted. Audit information stored in one location is vulnerable to accidental or incidental deletion or alteration.
Verify the audit records, at a minimum, are off-loaded for interconnected systems in real time and off-loaded for standalone systems weekly. If they are not, this is a finding.
Configure the system to, at a minimum, off-load audit records of interconnected systems in real time and off-load standalone systems weekly.