Protecting Log Information

Information

Logging facilities and log information must be protected against tampering and unauthorized access. Administrator and operator logs are often targets for erasing trails of activities.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Common controls for protecting log information include the following:
-Verifying that audit trails are enabled and active for system components
-Ensuring that only individuals who have a job-related need can view audit trail files
-Confirming that current audit trail files are protected from unauthorized modifications via access control mechanisms, physical segregation, and/or network segregation
-Ensuring that current audit trail files are promptly backed up to a centralized log server or media that is difficult to alter
-Verifying that logs for external-facing technologies (for example, wireless, firewalls, DNS, mail) are offloaded or copied onto a secure centralized internal log server or media
-Using file integrity monitoring or change detection software for logs by examining system settings and monitored files and results from monitoring activities
-Obtaining and examining security policies and procedures to verify that they include procedures to review security logs at least daily and that follow-up to exceptions is required
-Verifying that regular log reviews are performed for all system components
-Ensuring that security policies and procedures include audit log retention policies and require audit log retention for a period of time, defined by the business and compliance requirements

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-1, 800-53|AU-2, 800-53|AU-3, 800-53|AU-4, 800-53|AU-5, 800-53|AU-6, 800-53|AU-7, 800-53|AU-9, 800-53|AU-11, 800-53|AU-12, 800-53|AU-14, 800-53|SI-4

Plugin: amazon_aws

Control ID: 02712928415c1267645b6ca9d84a20d409db75eda5d45649d6f3165dcd92742c