NIST Special Publication 800-92
NIST Special Publication 800-92, "Guide to Computer Security Log Management," establishes guidelines and recommendations for securing and managing sensitive log data. The publication was prepared by Karen Kent and Murugiah Souppaya of the National Institute of Science and Technology and published under the SP 800-Series;[1] a repository of best practices for the InfoSec community. Log management is essential to ensuring that computer security records are stored in sufficient detail for an appropriate period of time.[2]
Background
Effective security event logging and log analysis is a critical component of any comprehensive security program within an organization. It is used to monitor system, network and application activity. It serves as a deterrent for unauthorized activity, as well as to provide a means to detect and analyze an attack in order to allow the organization to mitigate or prevent similar attacks in the future. However, security professionals have a significant challenge to determine what events must be logged, where and how long to retain those logs, and how to analyze the enormous amount of information that can be generated. A deficiency in any of these areas can cause an organization to miss signs of unauthorized activity, intrusion, and loss of data, which creates additional risk.[3]
Scope
NIST SP 800-92 provides a high-level overview and guidance for the planning, development and implementation of an effective security log management strategy. The intended audience for this publication include the general information security (InfoSec) community involved in incident response, system/application/network administration and managers.[2]
NIST SP 800-92 defines a log management infrastructure as having 4 major functions:[4]
- General - log parsing, event filtering and event aggregation;
- Log Storage - rotation, archival, compression, reduction, normalization, integrity checking;
- Log Analysis - event correlation, viewing and reporting;
- Disposal - clearing;
NIST SP 800-92 address the following security log management challenges:
- Log volume exceeding the rate of analysis;
- Ensuring immutability during storage and transmission;
- Inconsistent vendor log formats;
- Importance of a consistent review schedule;
- Retention issues involving purging, long term storage, and cost;
NIST SP 800-92 makes the following recommendations for security log management:[5]
- Establish policies and procedures for log management;
- Prioritize log management appropriately throughout the organization;
- Create and maintain a log management infrastructure;
- Provide proper support for all staff with log management responsibilities;
- Establish standard log management operational processes;
Compliance
The following federal regulations require the proper handling and storage of sensitive log data:
- HIPAA (Health Insurance Portability and Accountability Act of 1996). Requires the mandatory safeguard of personal health information.[6]
- SOX (Sarbanes-Oxley Act of 2002). Requires the mandatory record keeping of financial and IT log related data.[7]
- GLBA (Gramm-Leach-Bliley Act). Requires mandatory PII (Personal Identifiable Information) data protection.[8]
- PCI DSS (Payment Card Industry Data Security Standard). Requires the mandatory protection of consumer credit card information including storage and transmission.[9]
- FISMA (Federal Information Security Management Act of 2002). Stipulates federal requirements for managing government network systems and data. Log management guidelines include the generation, review, protection and retention of audit records, as well as the actions to be taken because of audit failure.[4]
References
- "NIST Publications". NIST Computer Security Resource Center. NIST. Retrieved 26 February 2015.
- Kent, Karen; Souppaya, Murugiah (2006). "Guide to Computer Security Log Management" (PDF). NIST SP 800-92: ES-1,1-1. Retrieved 26 February 2015.
- Butler, Vincent; Dorsey, Tom; Robinson, Ken (August 3, 2014). "Building a Logging Strategy for Effective Analysis": 3. Cite journal requires
|journal=
(help) - Kent, Karen; Souppaya, Murugiah (2006). "Guide to Computer Security Log Management" (PDF). NIST SP 800-92: 3-3,3-4. Retrieved 26 February 2015.
- Radack, Shirley. "Editor". ITL.NIST.gov. NIST. Retrieved 26 February 2015.
- "Summary of HIPAA Security Rule". Summary of the HIPAA Security Rule. Health and Human Services. Retrieved 26 February 2015.
- "Sarbanes-Oxley Act of 2002". A Guide to the Sarbanes-Oxley Act. Addison-Hewitt.
- "Gramm-Leach-Bliley Act (Privacy of Consumer Financial Information" (PDF). FDIC.gov. FDIC. Retrieved 26 February 2015.
- "Payment Card Industry Data Security Standard" (PDF). Security Standards Council. 3 (0). 2013. Retrieved 26 February 2015.