QS0027-01: Log Management Policy Flashcards

1
Q

QS0027-01: Log Management Policy

How long should logs be retained?

A

Retain logs for a minimum of 45 days.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

QS0027-01: Log Management Policy

What should be included in log contents?

A
  1. User identification
  2. Date and time of the event
  3. Component of the information system (e.g., software component, a hardware component) where the event occurred
  4. Type of event
  5. Subject identity
  6. Outcome of the event
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

QS0027-01: Log Management Policy

What security events should be logged?

A

SOP has a lot of details, but in summary, configuration changes to auditing, roles, user setup. All login attempts and logouts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly