- Information Security Handbook
- Darren Death
- 211字
- 2021-07-02 21:55:56
Auditing and accountability policy
Auditing and accountability policies establish the rules for how an information system securely alerts, records, stores, and allows access to auditable events important to information security. This policy also provides rules around audit log management that allow the high volume of audit logs that an information system produces to be manageable by the information security professional.
An auditing and accountability policy should address:
- Creating, protecting, and retaining information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity
- Ensuring that the actions of inpidual information system users can be uniquely traced to those users so they can be held accountable for their actions
- Reviewing and updating audited events
- Alerting in the event of an audit process failure
- Correlating audit review, analysis, and reporting of processes for investigation and response to indications of inappropriate, suspicious, or unusual activity
- Providing audit reduction and report generation to support on-demand analysis and reporting
- Providing an information system capability that compares and synchronizes internal system clocks with an authoritative source to generate timestamps for audit records
- Protecting audit information and audit tools from unauthorized access, modification, and deletion
- Limiting management of audit functionality to a subset of privileged users
推薦閱讀
- 三菱FX3U/5U PLC從入門到精通
- AutoCAD快速入門與工程制圖
- Natural Language Processing Fundamentals
- 程序設(shè)計語言與編譯
- 信息物理系統(tǒng)(CPS)測試與評價技術(shù)
- Enterprise PowerShell Scripting Bootcamp
- 中國戰(zhàn)略性新興產(chǎn)業(yè)研究與發(fā)展·智能制造裝備
- Mastering Geospatial Analysis with Python
- JRuby語言實(shí)戰(zhàn)技術(shù)
- Practical AWS Networking
- FANUC工業(yè)機(jī)器人虛擬仿真教程
- Microsoft System Center Data Protection Manager Cookbook
- DynamoDB Applied Design Patterns
- Eclipse RCP應(yīng)用系統(tǒng)開發(fā)方法與實(shí)戰(zhàn)
- Practical Network Automation