San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

AU-4 Audit Log Storage Capacity

Audit and Accountability family. 4 Control Correlation Identifiers map to this control, and 34 STIG rules implement those CCIs.

0CAT I (high)
31CAT II (medium)
3CAT III (low)
4CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to AU-4
Red Hat Enterprise Linux 9V211
Red Hat Enterprise Linux 8V27
Microsoft Windows Server 2019V35
Microsoft Windows Server 2022V25
Microsoft Windows 10V33
Microsoft Windows 11V23

Control Correlation Identifiers mapped to AU-4

CCIDefinitionRev
CCI-001848Defines the audit log retention requirements for allocating audit log storage capacity.5, 4
CCI-001849Allocate audit log storage capacity to accommodate organization-defined audit log retention requirements.5, 4
CCI-001850Defines the frequency to off-load audit records onto a different system or media than the system being audited.5, 4
CCI-001851Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging.5, 4

STIG rules that implement AU-4

RuleSTIG IDSeverityRequirement
V-205796WN19-CC-000270mediumWindows Server 2019 Application event log size must be configured to 32768 KB or greater.
V-205797WN19-CC-000280mediumWindows Server 2019 Security event log size must be configured to 196608 KB or greater.
V-205798WN19-CC-000290mediumWindows Server 2019 System event log size must be configured to 32768 KB or greater.
V-205799WN19-AU-000010mediumWindows Server 2019 audit records must be backed up to a different system or media than the system being audited.
V-205843WN19-AU-000020mediumWindows Server 2019 must, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly.
V-220779WN10-AU-000500mediumThe Application event log size must be configured to 32768 KB or greater.
V-220780WN10-AU-000505mediumThe Security event log size must be configured to 1024000 KB or greater.
V-220781WN10-AU-000510mediumThe System event log size must be configured to 32768 KB or greater.
V-230394RHEL-08-030062mediumRHEL 8 must label all off-loaded audit logs before sending them to the central log server.
V-230469RHEL-08-030602lowRHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
V-230476RHEL-08-030660mediumRHEL 8 must allocate audit record storage capacity to store at least one week of audit records, when audit records are not immediately sent to a central audit record storage facility.
V-230479RHEL-08-030690mediumThe RHEL 8 audit records must be off-loaded onto a different system or storage media from the system being audited.
V-230480RHEL-08-030700mediumRHEL 8 must take appropriate action when the internal event queue is full.
V-230481RHEL-08-030710mediumRHEL 8 must encrypt the transfer of audit records off-loaded onto a different system or media from the system being audited.
V-230482RHEL-08-030720mediumRHEL 8 must authenticate the remote logging server for off-loading audit logs.
V-253337WN11-AU-000500mediumThe Application event log size must be configured to 32768 KB or greater.
V-253338WN11-AU-000505mediumThe Security event log size must be configured to 1024000 KB or greater.
V-253339WN11-AU-000510mediumThe System event log size must be configured to 32768 KB or greater.
V-254294WN22-AU-000010mediumWindows Server 2022 audit records must be backed up to a different system or media than the system being audited.
V-254295WN22-AU-000020mediumWindows Server 2022 must, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly.
V-254358WN22-CC-000270mediumWindows Server 2022 Application event log size must be configured to 32768 KB or greater.
V-254359WN22-CC-000280mediumWindows Server 2022 Security event log size must be configured to 196608 KB or greater.
V-254360WN22-CC-000290mediumWindows Server 2022 System event log size must be configured to 32768 KB or greater.
V-257847RHEL-09-231030lowRHEL 9 must use a separate file system for the system audit data path.
V-258140RHEL-09-652010mediumRHEL 9 must have the rsyslog package installed.
V-258146RHEL-09-652040mediumRHEL 9 must authenticate the remote logging server for offloading audit logs via rsyslog.
V-258147RHEL-09-652045mediumRHEL 9 must encrypt the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
V-258148RHEL-09-652050mediumRHEL 9 must encrypt via the gtls driver the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.
V-258149RHEL-09-652055mediumRHEL 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog.
V-258155RHEL-09-653030mediumRHEL 9 must allocate audit record storage capacity to store at least one week's worth of audit records.
V-258161RHEL-09-653060mediumRHEL 9 must label all offloaded audit logs before sending them to the central log server.
V-258162RHEL-09-653065mediumRHEL 9 must take appropriate action when the internal event queue is full.
V-258173RHEL-09-653120lowRHEL 9 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.
V-258175RHEL-09-653130mediumRHEL 9 audispd-plugins package must be installed.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AU-4. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.