Protecting Log Information

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Logging facilities and log information must be protected against tampering and unauthorized access. Administrator and operator logs are often targets for erasing trails of activities.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Common controls for protecting log information include the following:
-Verifying that audit trails are enabled and active for system components
-Ensuring that only individuals who have a job-related need can view audit trail files
-Confirming that current audit trail files are protected from unauthorized modifications via access control mechanisms, physical segregation, and/or network segregation
-Ensuring that current audit trail files are promptly backed up to a centralized log server or media that is difficult to alter
-Verifying that logs for external-facing technologies (for example, wireless, firewalls, DNS, mail) are offloaded or copied onto a secure centralized internal log server or media
-Using file integrity monitoring or change detection software for logs by examining system settings and monitored files and results from monitoring activities
-Obtaining and examining security policies and procedures to verify that they include procedures to review security logs at least daily and that follow-up to exceptions is required
-Verifying that regular log reviews are performed for all system components
-Ensuring that security policies and procedures include audit log retention policies and require audit log retention for a period of time, defined by the business and compliance requirements

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-1, 800-53|AU-2, 800-53|AU-3, 800-53|AU-4, 800-53|AU-5, 800-53|AU-6, 800-53|AU-7, 800-53|AU-9, 800-53|AU-11, 800-53|AU-12, 800-53|AU-14, 800-53|SI-4

Plugin: amazon_aws

Control ID: 02712928415c1267645b6ca9d84a20d409db75eda5d45649d6f3165dcd92742c