DoD STIGs – V-32256

Overview:

Title: The DBMS must have allocated audit record storage capacity.

Vulnerability ID: V-32256

STIG ID:

IA Controls: None

Severity: medium

Description: Applications need to be cognizant of potential audit log storage capacity issues. During the installation and/or configuration process, applications should detect and determine if adequate storage capacity has been allocated for audit logs.

During the installation process, a notification may be provided to the installer indicating, based on the auditing configuration chosen and the amount of storage space allocated for audit logs, the amount of storage capacity available is not sufficient enough to meet storage requirements.

When insufficient space in directories is allocated for audit records, database audit logs can fill up and begin to overwrite earlier logs, database activity can stop altogether, or auditing could fail and crucial tracking data could be lost.

Check Text: Verify storage capacity for audit records generated by the database. If no storage space is specifically allocated for database audit records, this is a finding.

Fix Text: Specifically allocate appropriate storage space for audit logs.

[divider]

Interpreting V-32256:

Coming Soon!

Return to the DoD STIGs – Database Security Requirements Guide

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.