官术网_书友最值得收藏!

Auditing and accountability policy

Auditing and accountability policies establish the rules for how an information system securely alerts, records, stores, and allows access to auditable events important to information security. This policy also provides rules around audit log management that allow the high volume of audit logs that an information system produces to be manageable by the information security professional.

An auditing and accountability policy should address:

  • Creating, protecting, and retaining information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity
  • Ensuring that the actions of inpidual information system users can be uniquely traced to those users so they can be held accountable for their actions
  • Reviewing and updating audited events
  • Alerting in the event of an audit process failure
  • Correlating audit review, analysis, and reporting of processes for investigation and response to indications of inappropriate, suspicious, or unusual activity
  • Providing audit reduction and report generation to support on-demand analysis and reporting
  • Providing an information system capability that compares and synchronizes internal system clocks with an authoritative source to generate timestamps for audit records
  • Protecting audit information and audit tools from unauthorized access, modification, and deletion
  • Limiting management of audit functionality to a subset of privileged users
主站蜘蛛池模板: 石河子市| 玉溪市| 横峰县| 连山| 安吉县| 伊春市| 乐陵市| 绍兴市| 定边县| 雷山县| 萨嘎县| 城固县| 仁怀市| 马龙县| 水富县| 镇宁| 曲松县| 宿松县| 潼关县| 庄河市| 吉木萨尔县| 禄劝| 浦北县| 深水埗区| 阜阳市| 遵义市| 吕梁市| 旌德县| 开江县| 镇安县| 广安市| 奈曼旗| 青州市| 镇雄县| 彝良县| 广汉市| 长宁县| 盐亭县| 息烽县| 广东省| 水富县|