Auditing Flashcards
1
Q
Two requirements for auditing?
A
Event definition
Event detection
2
Q
What are the three types of audit trail analysis?
A
Audit trail review after event.
Periodic review of audit trail data.
Real-time audit trail analysis (part of intrusion detection function)
3
Q
What are three ways to protect audit trail data?
Which is most vulnerable to intruder attack? Impractical but permanent? Most secure?
A
- Read/write file on host: most vulnerable
- Write-only device: paper trail, impractical for detailed audits but permanent.
- Write-once/read-many device: most secure but delayed access.