Rule version BCAS-ND-001630 · STIG v1 · 2026-09-16
It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without a real-time alert, security personnel may be unaware of an impending failure of the audit capability and system operation may be adversely affected.
Alerts provide organizations with urgent messages. Real-time alerts provide these messages immediately (i.e., the time from event detection to alert occurs in seconds or less).
Satisfies: SRG-APP-000360-NDM-000295, SRG-APP-000795-NDM-000130
Verify "email-alerts" servers are configured with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "show running-config alerts". 3. Review the output to verify a sender, recipient, and SMTP server are defined.
If there are no "email-alerts" servers configured or the settings are incomplete, this is a finding.
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable", enter the password, and then enter "configure terminal". 3. Configure the alert sender and recipient addresses (replacing bracketed text with site values) by entering: "alerts email-alerts addresses sender [SENDER_EMAIL]" "alerts email-alerts addresses recipients to [SA_ISSO_EMAIL]" 4. Configure the SMTP server and connection settings by entering: "alerts email-alerts server-settings server [SERVER_IP_OR_HOSTNAME]" "alerts email-alerts server-settings encryption port [PORT]" 5. Configure the SMTP service account authentication by entering: "alerts email-alerts authentication username [USER]" "alerts email-alerts authentication password [PASSWORD]" 6. Enforce secure SMTP encryption by entering: "alerts email-alerts server-settings encryption type StartTLS" (replace with TLS if the gateway requires strict TLS) "alerts email-alerts server-settings encryption verify-certificate true" 7. Enter "exit" and then "exit" again to leave configuration mode.