Log Reviews

4 slides · 2 min read · Domain 6

Log Reviews

All of the major controls frameworks emphasize the importance of organizational logging practices.

ISO 27001:2013 control 12.4.1 addresses event logging and states the following, "Event logs recording user activities, exceptions, faults and information security events should be produced, kept and regularly reviewed."

Information that may be relevant to being recorded and reviewed include (and is not limited to) user IDs, system activities, dates/times of key events (for example, log-on and log-off), device and location identity, successful and rejected system and resource access attempts, system configuration changes, and system protection activation and deactivation events.

NIST SP 800-92 identifies log reviews as being a component of log management. Log reviews are an imperative function not only related to security assessment and testing but also to identifying security incidents, policy violations, fraudulent activities, and operational problems near to the time of occurrence. Log reviews support audits, forensic analysis related to internal and external investigations, and provide support for organizational security baselines. Review of historic audit logs can determine if a vulnerability identified in a system has been previously exploited.

The following are some prominent regulations that drive the need for diligent log reviews:

Gramm-Leach-Bliley Act (GLBA)

Because a primary tenant of GLBA is the requirement for financial institutions to protect customer information, log review can be utilized to identify and rectify security violations.

Sarbanes-Oxley Act (SOX) of 2002

SOX regulates accurate financial and accounting practices. SOX regulatory requirements are supported by a regular review of logs with a view to locating security violations and appropriate retention of logs and records for future review.

Health Insurance Portability And Accountability Act of 1996 (HIPAA)

HIPAA maintains specific security practices to protect health information related to patients. Related to the protection of health information are specific activities that include regular reviews of audit logs and access reports and that documentation of these activities needs to be retained for a minimum of six years.

Payment Card Industry Data Security Standard (PCI DSS)

PCI DSS mandates the security for organizations that stores, processes, or transmits credit card data. A primary responsibility for a processor of credit card data is to track all network resource access and cardholder data.

Test this domain