• No results found

AUDIT LOGGING/LOG MANAGEMENT

N/A
N/A
Protected

Academic year: 2021

Share "AUDIT LOGGING/LOG MANAGEMENT"

Copied!
30
0
0

Loading.... (view fulltext now)

Full text

(1)

1

AUDIT LOGGING/LOG

/

MANAGEMENT

KATHLEEN A MULLIN, MBA, KATHLEEN A MULLIN, MBA, CIA, CISA, CISSP, ISA, CISM, CRISC, CGEIT

DIRECTOR OF IT SECURITY/CISO HEALTHPLAN SERVICES (HPS)

AHIA 31st Annual Conference – August 26-29, 2012 – Philadelphia PA

(2)

Key Points

y

… When is log information important and what Audit

2

needs to focus on

… Where to look for additional information to interpret

log data log data

… What actions should be taken by which role within the

organization W

… What are the appropriate actions based on the log

data

… What is appropriate without a logging tool pp p gg g

(3)

When is log information important?

g

p

(4)

What to focus on

… Information Overload

4

† Business Impact Analysis † Risk

… Requirements

† Operational † Business

(5)

Appropriate deployments

pp p

p y

… Project Approach 5 † Platform † Business † Geographic † Geographic † Stability † Resource

(6)

What to Log

g

… Syslog Events … Access Logs

6

y g

… Windows Log Events

… Database Logs

g

… IDS / IPS Logs … Firewall Logs g … System Logs … Error Logs g … Network Flows … Security Logs g … Application Logs … Patch Logs y g … Backup Logs … Anti-Malware Logs g

… Policy Change Logs

g

(7)

Log Reporting – What to focus on

g

p

g

…

SANS Top 5 Log Reports

7

…

SANS Top 5 Log Reports

† Attempts to Gain Access through Existing Accounts † Failed File or Resource Access Attemptsp

† Unauthorized Changes to Users, Groups and Services † Systems Most Vulnerable to Attack

(8)

Where to look for additional

i f

ti t i t

t l d t

information to interpret log data

(9)

Where to look for additional

i f

ti t i t

t l d t

information to interpret log data

… Vendors 9 … Vendors … Search Engines … Search Engines Addi i l R … Additional Resources

(10)

What actions should be taken by which

l ithi th

i ti

(11)

What actions should be taken by which

l ithi th

i ti

role within the organization

11

… IT … Compliance

… IT

… Information Security

… Incident Response Team

… Compliance

… Audit

… Finance

… Incident Response Team

… Business Process Owner

Ri k

… Finance

… Legal

H R

… Risk … Human Resources

(12)

What actions should be taken by which

l ithi th

i ti

(13)

What actions should be taken by which

l ithi th

i ti

role within the organization

(14)

What actions should be taken by which

l ithi th

i ti

(15)

What are the appropriate actions

b

d

th l

d t

based on the log data

15 … RISK … RISK † Operational requirements † Contractual requirements † Contractual requirements † Insurance requirements † Change Managementg g … RISK

† Incident Response Planc de espo se a † Disaster Recovery Plans † Business Continuity Plansy

(16)

What are the appropriate actions

b

d

th l

d t

based on the log data

16 … Environmental Norm … Environmental Norm † Critical † Error † Error

(17)

What to do without a logging tool and

h t t l k f i

l

i t l

what to look for in a logging tool

(18)

What to do without a logging tool

gg g

18

RISK Based

RISK Based

… Operational requirements … Contractual requirements … Insurance requirements

(19)

What to look for in a logging tool

gg g

… Collect, Index- … Scalability

19 … Collect, Index Correlate … Alert … Scalability … Tuning … Analytics … Alert … Store … Report … Analytics … Segregation of duties … Report

(20)

What to look for in a logging tool

gg g

20

… Integration with work order systems … Integration with work order systems … File Integrity Monitoring

… Security Monitoring and Reporting … Security Monitoring and Reporting … Fraud Detection

D l d i

(21)

Summaryy

21

… When is log information important and what Audit needs g p

to focus on

… Where to look for additional information to interpret log

d t data

… What actions should be taken by which role within the

organizationg

… What are the appropriate actions based on the log data … What is appropriate without a logging tool

… what organizations should evaluate when looking for a

(22)

Additional Resources - ISACA

ISACA http://www.isaca.org/ 22 „ CoBIT 4.1 „ http://www.isaca.org/Knowledge-Center/cobit/Pages/Overview.aspx „ CoBIT 5.0 h // /COBIT/P / f „ http://www.isaca.org/COBIT/Pages/info-sec.aspx „ The Risk IT Framework

(23)

Additional Resources - NIST

… NIST

23

† http://csrc.nist.gov/

„ Guide to Computer Security Log Management

„ http://csrc nist gov/publications/nistpubs/800 92/SP800 92 pdf „ http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf „ Recommended Security Controls for Federal Information Systems and

Organizations

„ http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-„ http://csrc.nist.gov/publications/nistpubs/800 53 Rev3/sp800 53

(24)

Additional Resources e-discoveryy

… Discovery Resources

24

y

† http://www.discoveryresources.org/

„ State by State Summary Report of E-Discovery Efforts

„ http://www discoveryresources org/library/case law and „

(25)

http://www.discoveryresources.org/library/case-law-and-Additional Resources - Microsoft

… Microsoft 25 … Microsoft † http://www.ultimatewindowssecurity.com/Default.aspx † http://www.eventid.net/p // / † http://technet.microsoft.com/en-us/default.aspx † http://support.microsoft.com/

(26)

Additional Resources – Best Practices

…

SANS

26

…

SANS

† Critical Control 14: Maintenance, Monitoring, and Analysis of

Security Audit Logs

„

http://www.sans.org/critical-security-controls/control.php?id=14

† Top 5 Essential Log Reports † Top 5 Essential Log Reports

„ http://www.sans.org/security-resources/top5-logreports.pdf

…

The Unified Compliance Framework (UCF)

(27)

Additional Resources

27

… PCI Data Security Standards

† https://www.pcisecuritystandards.org/

† https://www.pcisecuritystandards.org/security standards/documentsp // p y g/ y_ /

.php

… Kerberos

† http://www.rfc-editor.org/rfc/rfc1510.txt

… Microsoft PowerShell for Windows Server 2003

† http://www.microsoft.com/downloads/details.aspx?FamilyId=10EE29AF-7C3A-4057-8367-C9C1DAB6E2BF&displaylang=en

(28)
(29)

Thank-you

y

29

(30)

Save the Date: August 25-28 2013 August 25-28, 2013 32nd Annual Conference Chi IL Chicago, IL

References

Related documents

Poleg mobilne Android aplikacije je bila izdelana tudi spletna aplikacija, ki sluˇ zi kot vmesnik za dostop do najljubˇsih poti in upravljanje z njimi. Razvoj aplikacije je potekal

V izvornih sistemih se lahko pri vnosu pogodbe zgodijo napake (npr. Sila nerodno bi bilo, da se zaradi pravila o zajemu prometa v izvornih sistemih po odpravi napake

No-root Differentiated Resource Management Node Workflow Based Environments Supercomputers Undifferentiated Resources Z-Series Intra, Inter and Extra Cloud Resources LPAR...

For (embedded) software debug, under the condition that a prototype board with the adequate processor and set of peripherals exists (if it not the case, you’d better

Given the significant health consequences of social isolation and loneliness on older adults, and the high prevalence of chronic musculoskeletal pain in this population, such

Uniform flow; most economical cross-section; discharge; velocity; erosion;

Interference with xenobiotic metabolic activity by the commonly used vehicle solvents dimethylsulfoxide and methanol in zebrafish (Danio rerio) larvae but not Daphnia magna..

Methods: Using emergency department visits data, we illustrated and compared the additive and multiplicative hazards models for analysis of recurrent event durations under (i) a