|
LogAnalysis
[logs] SIM solution - Objectives ? May 24 2007 05:52AM saudi sans (saudisans gmail com) (3 replies) Re: [logs] SIM solution - Objectives ? May 24 2007 12:58PM Ron Gula (rgula tenablesecurity com) (1 replies) Re: [logs] SIM solution - Objectives ? May 25 2007 01:29PM saudi sans (saudisans gmail com) (3 replies) RE: [logs] SIM solution - Objectives ? May 25 2007 06:47PM Tina Bird (tbird precision-guesswork com) (1 replies) RE: [logs] SIM solution - Objectives ? May 28 2007 01:00AM Marcus J. Ranum (mjr ranum com) (1 replies) Re: [logs] SIM solution - Objectives ? May 25 2007 05:50PM Paul Melson (pmelson gmail com) (1 replies) Re: [logs] SIM solution - Objectives ? (Firewall logging) May 25 2007 06:35PM Ron Gula (rgula tenablesecurity com) (2 replies) Re: [logs] SIM solution - Objectives ? (Firewall logging) May 27 2007 03:23PM Paul Melson (pmelson gmail com) (2 replies) Re: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 03:43PM Dave Ellingsberg (Dave Ellingsberg csu mnscu edu) (1 replies) RE: [logs] SIM solution - Objectives ? (Firewall logging) May 30 2007 01:31PM Paul Melson (pmelson gmail com) Re: [logs] SIM solution - Objectives ? (Firewall logging) May 27 2007 09:02PM Marcus J. Ranum (mjr ranum com) (3 replies) RE: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 07:20PM Eric Fitzgerald (Eric Fitzgerald microsoft com) Re: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 05:17PM Chris Brenton (cbrenton chrisbrenton org) (1 replies) Re: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 08:53PM Marcus J. Ranum (mjr ranum com) [logs] SIM solution - Objectives ? (Firewall logging) May 28 2007 05:59PM Fenwick, Wynn (wynn fenwick cgi com) (2 replies) RE: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 07:07PM Paul Melson (pmelson gmail com) (1 replies) RE: [logs] SIM solution - Objectives ? (Firewall logging) May 30 2007 03:40PM Fenwick, Wynn (wynn fenwick cgi com) (1 replies) Re: [logs] SIM solution - Objectives ? (Firewall logging) May 25 2007 07:22PM Jimmy Alderson (jimmy alderson gmail com) |
|
Privacy Statement |
COSO, CoBIT, and )they are not
> prescriptive on the period of reconciliation.
>
> ISO17799-s10.10.2 (this could be old) calls for the creation of procedures
to monitor system use, and
> review of the results of this monitoring shall happen regularly,
including:
> * Authorized access,
> * Privileged operations,
> * Unauthorized access attempts,
> * System alerts or failures, and
> * Changes to, or attempts to change, system security settings and
controls.
>
> And yes, unless you wash the feet of the auditors after they step over the
palm branches laid before
> them, "good enough" should suffice.
I have to disagree and say that BS/ISO 17799 requires time frames
(SLA's/OLA's) for both monitoring and review to take place and that a
response to any exceptions be initiated. This is covered in 8.1.3 in the
context of incident response and investigation. If you go the CoBIT/ITIL
route, you will have to build additional controls around those time frames
to prove that you're performing the review and the response and that you're
doing both within the windows that you say you are. And at least where I
work, both our internal auditors and our third-party auditors (from a Big 3
firm) ask for this proof.
So, can you build something that is brainlessly 'compliant' using a rigidly
literal interpretation of a standard combined with very weak internal P&P
documents? Of course. But it's just teaching to the test. You're not
accomplishing anything. You're doing work solely to make auditors happy.
At that point your cart is so far out ahead that your horse can't see it
anymore.
PaulM
_______________________________________________
LogAnalysis mailing list
LogAnalysis (at) loganalysis (dot) org [email concealed]
http://www.loganalysis.org/mailman/listinfo/loganalysis
[ reply ]