CSCv7|6.7

Title

Regularly Review Logs

Description

On a regular basis, review logs to identify anomalies or abnormal events.

Reference Item Details

Category: Maintenance, Monitoring and Analysis of Audit Logs

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.7 Ensure logging data is monitoredJuniperCIS Juniper OS Benchmark v2.1.0 L1
2.1 Ensure monitoring and alerting exist for ACCOUNTADMIN and SECURITYADMIN role grantsSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.1 Ensure That Cloud Audit Logging Is Configured ProperlyGCPCIS Google Cloud Platform v3.0.0 L1
2.2 Ensure monitoring and alerting exist for MANAGE GRANTS privilege grantsSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.3 Ensure monitoring and alerting exist for password sign-ins of SSO usersSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.4 Ensure monitoring and alerting exist for password sign-in without MFASnowflakeCIS Snowflake Foundations v1.0.0 L1
2.5 Ensure monitoring and alerting exist for creation, update and deletion of security integrationsSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.6 Ensure monitoring and alerting exist for changes to network policies and associated objectsSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.7 Ensure monitoring and alerting exist for SCIM token creationSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.8 Ensure monitoring and alerting exists for new share exposuresSnowflakeCIS Snowflake Foundations v1.0.0 L1
2.9 Ensure monitoring and alerting exists for sessions from unsupported Snowflake Connector for Python and JDBC and ODBC driversSnowflakeCIS Snowflake Foundations v1.0.0 L2
2.12 Ensure That Cloud DNS Logging Is Enabled for All VPC NetworksGCPCIS Google Cloud Platform v3.0.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum SizeUnixCIS Apple macOS 13.0 Ventura Cloud-tailored v1.1.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum SizeUnixCIS Apple macOS 15.0 Sequoia v1.0.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum SizeUnixCIS Apple macOS 14.0 Sonoma v2.0.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum SizeUnixCIS Apple macOS 12.0 Monterey v4.0.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum SizeUnixCIS Apple macOS 11.0 Big Sur v4.0.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum SizeUnixCIS Apple macOS 13.0 Ventura v3.0.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum SizeUnixCIS Apple macOS 12.0 Monterey Cloud-tailored v1.0.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum SizeUnixCIS Apple macOS 14.0 Sonoma Cloud-tailored v1.1.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum Size - all_maxUnixCIS Apple macOS 10.14 v2.0.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum Size - all_maxUnixCIS Apple macOS 10.15 Catalina v3.0.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum Size - ttlUnixCIS Apple macOS 10.15 Catalina v3.0.0 L1
3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum Size - ttlUnixCIS Apple macOS 10.14 v2.0.0 L1
3.4 Ensure Security Auditing Retention Is EnabledUnixCIS Apple macOS 11.0 Big Sur v4.0.0 L1
3.4 Ensure Security Auditing Retention Is EnabledUnixCIS Apple macOS 15.0 Sequoia v1.0.0 L1
3.4 Ensure Security Auditing Retention Is EnabledUnixCIS Apple macOS 12.0 Monterey Cloud-tailored v1.0.0 L1
3.4 Ensure Security Auditing Retention Is EnabledUnixCIS Apple macOS 13.0 Ventura Cloud-tailored v1.1.0 L1
3.4 Ensure Security Auditing Retention Is EnabledUnixCIS Apple macOS 13.0 Ventura v3.0.0 L1
3.4 Ensure Security Auditing Retention Is EnabledUnixCIS Apple macOS 14.0 Sonoma v2.0.0 L1
3.4 Ensure Security Auditing Retention Is EnabledUnixCIS Apple macOS 12.0 Monterey v4.0.0 L1
3.4 Ensure Security Auditing Retention Is EnabledUnixCIS Apple macOS 10.14 v2.0.0 L1
3.4 Ensure Security Auditing Retention Is EnabledUnixCIS Apple macOS 10.15 Catalina v3.0.0 L1
3.4 Ensure Security Auditing Retention Is EnabledUnixCIS Apple macOS 14.0 Sonoma Cloud-tailored v1.1.0 L1
3.7 Ensure proxies pass source IP information - X-Real-IPUnixCIS NGINX Benchmark v2.1.0 L1 Loadbalancer
3.7 Ensure proxies pass source IP information - X-Real-IPUnixCIS NGINX Benchmark v2.1.0 L1 Proxy
3.9 Review and Log Implied RulesCheckPointCIS Check Point Firewall L2 v1.1.0
4.1 Ensure unauthorized API calls are monitoredamazon_awsCIS Amazon Web Services Foundations v4.0.1 L2