Audit Log Management Policy

 

Purpose 

The purpose of the audit log management policy is to create, store, and analyse log files with the goal of detecting and responding to any suspicious or abnormal events that may occur within the organisation. It also allows for the prioritising, and remediating of any potential vulnerabilities in enterprise systems and software. The audit log management policy provides the processes and procedures for ensuring logs are created and properly analysed. This policy applies to all departments and all assets connected to the Evercam network.

Responsibility 

The Information Technology (IT) department is responsible for all log management functions. Specifically, administrators are responsible for configuring the correct devices to generate, store, and transmit logs. IT is responsible for informing all users of their responsibilities in the use of any assets assigned to them, such as applying updates in a regular manner or restarting their systems. All enterprise assets are required to comply with the enterprise audit logging procedures.

Policy 

Generation

  1. An enterprise-wide strategy must be developed to establish and maintain an audit log process. 
    • This strategy must be documented.
    • Documentation must be updated annually, or when significant changes have occurred. 
    • The contents of logs must be specified within the secure configuration policy. 
  2. Audit logging must be enabled on all enterprise assets, as is practical.
  3. Audit logs must not be disabled on enterprise assets. 
  1.  

Transmission 

  1. Procedures must be developed to move logs from enterprise assets to an audit log datastore.
    • This may be done manually or via electronic means.
  2. Access controls must be used to prevent audit logs from being modified in an unauthorised manner. 

Storage

  1. Procedures must be developed to collect audit logs from enterprise assets. 
  2. Sufficient storage space must be allocated for audit logs for the period of time required for analysis and retention. 
    • Sufficient space must be allocated to store audit logs on all enterprise assets. 
    • Sufficient space must be allocated to store audit logs on any centralised audit log datastore. 
  3. Retention timeframes for audit logs should be in accordance with the enterprise data management process.

Review and Analysis 

  1. All high severity events must be acted upon in accordance with the audit log management process. 

Disposal 

  1. All audit logs must be stored for a period of time specified by the audit log management process. 
  2. Archived logs must be available for analysis. 
  3. Disposal of audit logs should be in accordance with the enterprise data management process.