QS0027-01: Log Management Policy Flashcards
1
Q
QS0027-01: Log Management Policy
How long should logs be retained?
A
Retain logs for a minimum of 45 days.
2
Q
QS0027-01: Log Management Policy
What should be included in log contents?
A
- User identification
- Date and time of the event
- Component of the information system (e.g., software component, a hardware component) where the event occurred
- Type of event
- Subject identity
- Outcome of the event
3
Q
QS0027-01: Log Management Policy
What security events should be logged?
A
SOP has a lot of details, but in summary, configuration changes to auditing, roles, user setup. All login attempts and logouts.