V-222488
Application Security and Development Security Technical Implementation Guide
Title
The application must provide the capability to filter audit records for events of interest based upon organization-defined criteria.
Description
<VulnDiscussion>The ability to specify the event criteria that are of interest provides the persons reviewing the logs with the ability to quickly isolate and identify these events without having to review entries that are of little or no consequence to the investigation. Without this capability, forensic investigations are impeded. Events of interest can be identified by the content of specific audit record fields including, for example, identities of individuals, event types, event locations,...
Fix Text (Documentation Requirement)
Configure the application filters to search event logs based on defined criteria.