{
    "control": "AU-4",
    "title": "Audit Log Storage Capacity",
    "ccis": [
        {
            "cci": "CCI-001848",
            "definition": "Defines the audit log retention requirements for allocating audit log storage capacity."
        },
        {
            "cci": "CCI-001849",
            "definition": "Allocate audit log storage capacity to accommodate organization-defined audit log retention requirements."
        },
        {
            "cci": "CCI-001850",
            "definition": "Defines the frequency to off-load audit records onto a different system or media than the system being audited."
        },
        {
            "cci": "CCI-001851",
            "definition": "Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging."
        }
    ],
    "rules_mapped": 34,
    "rules": [
        {
            "rule": "V-220779",
            "stig_id": "WN10-AU-000500",
            "title": "The Application event log size must be configured to 32768 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-220780",
            "stig_id": "WN10-AU-000505",
            "title": "The Security event log size must be configured to 1024000 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-220781",
            "stig_id": "WN10-AU-000510",
            "title": "The System event log size must be configured to 32768 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-253337",
            "stig_id": "WN11-AU-000500",
            "title": "The Application event log size must be configured to 32768 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-253338",
            "stig_id": "WN11-AU-000505",
            "title": "The Security event log size must be configured to 1024000 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-253339",
            "stig_id": "WN11-AU-000510",
            "title": "The System event log size must be configured to 32768 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-205796",
            "stig_id": "WN19-CC-000270",
            "title": "Windows Server 2019 Application event log size must be configured to 32768 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-205797",
            "stig_id": "WN19-CC-000280",
            "title": "Windows Server 2019 Security event log size must be configured to 196608 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-205798",
            "stig_id": "WN19-CC-000290",
            "title": "Windows Server 2019 System event log size must be configured to 32768 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-205799",
            "stig_id": "WN19-AU-000010",
            "title": "Windows Server 2019 audit records must be backed up to a different system or media than the system being audited.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-205843",
            "stig_id": "WN19-AU-000020",
            "title": "Windows Server 2019 must, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-254294",
            "stig_id": "WN22-AU-000010",
            "title": "Windows Server 2022 audit records must be backed up to a different system or media than the system being audited.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-254295",
            "stig_id": "WN22-AU-000020",
            "title": "Windows Server 2022 must, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-254358",
            "stig_id": "WN22-CC-000270",
            "title": "Windows Server 2022 Application event log size must be configured to 32768 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-254359",
            "stig_id": "WN22-CC-000280",
            "title": "Windows Server 2022 Security event log size must be configured to 196608 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-254360",
            "stig_id": "WN22-CC-000290",
            "title": "Windows Server 2022 System event log size must be configured to 32768 KB or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-230394",
            "stig_id": "RHEL-08-030062",
            "title": "RHEL 8 must label all off-loaded audit logs before sending them to the central log server.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-230469",
            "stig_id": "RHEL-08-030602",
            "title": "RHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-230476",
            "stig_id": "RHEL-08-030660",
            "title": "RHEL 8 must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-230479",
            "stig_id": "RHEL-08-030690",
            "title": "The RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-230480",
            "stig_id": "RHEL-08-030700",
            "title": "RHEL 8 must take appropriate action when the internal event queue is full.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-230481",
            "stig_id": "RHEL-08-030710",
            "title": "RHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-230482",
            "stig_id": "RHEL-08-030720",
            "title": "RHEL 8 must authenticate the remote logging server for off-loading audit logs.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-257847",
            "stig_id": "RHEL-09-231030",
            "title": "RHEL 9 must use a separate file system for the system audit data path.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001849"
            ]
        },
        {
            "rule": "V-258140",
            "stig_id": "RHEL-09-652010",
            "title": "RHEL 9 must have the rsyslog package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000154",
                "CCI-001851"
            ]
        },
        {
            "rule": "V-258146",
            "stig_id": "RHEL-09-652040",
            "title": "RHEL 9 must authenticate the remote logging server for offloading audit logs via rsyslog.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-258147",
            "stig_id": "RHEL-09-652045",
            "title": "RHEL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-258148",
            "stig_id": "RHEL-09-652050",
            "title": "RHEL 9 must encrypt via the gtls driver the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-258149",
            "stig_id": "RHEL-09-652055",
            "title": "RHEL 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-258155",
            "stig_id": "RHEL-09-653030",
            "title": "RHEL 9 must allocate audit record storage capacity to store at least one week's worth of audit records.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001849",
                "CCI-001851"
            ]
        },
        {
            "rule": "V-258161",
            "stig_id": "RHEL-09-653060",
            "title": "RHEL 9 must label all offloaded audit logs before sending them to the central log server.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000132",
                "CCI-001851"
            ]
        },
        {
            "rule": "V-258162",
            "stig_id": "RHEL-09-653065",
            "title": "RHEL 9 must take appropriate action when the internal event queue is full.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001851"
            ]
        },
        {
            "rule": "V-258173",
            "stig_id": "RHEL-09-653120",
            "title": "RHEL 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.",
            "severity": "low",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001464",
                "CCI-001849"
            ]
        },
        {
            "rule": "V-258175",
            "stig_id": "RHEL-09-653130",
            "title": "RHEL 9 audispd-plugins package must be installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001851"
            ]
        }
    ]
}