Free DISA STIG and SRG Library | Vaulted

V-96445

The Cisco router must generate an immediate alert when allocated audit record storage volume reaches 75% of repository maximum audit record storage capacity.

Finding ID
CISC-ND-000990
Rule ID
SV-105583r1_rule
Severity
Cat II
CCE
(None)
Group Title
SRG-APP-000359-NDM-000294
CCI
CCI-001855
Target Key
(None)
Documentable
No
Discussion

If security personnel are not notified immediately upon storage volume utilization reaching 75%, they are unable to plan for storage capacity expansion. This could lead to the loss of audit information. Note that while the network device must generate the alert, notification may be done by a management server.

Fix Text

Configure the router to send log messages to the syslog server as shown in the example below. RP/0/0/CPU0:R3(config)#logging 10.1.3.22 severity info

Check Content

The Cisco router is not compliant with this requirement. However, the risk associated with this requirement can be fully mitigated if the router is configured to send logs to a syslog server that can send alerts to the appropriate personnel. Verify that the router is configured to send logs to a syslog server. The configuration should look similar to the example below: logging 10.1.3.22 vrf default severity info If the router is not configured to send log messages to a syslog server, this is a finding.