CyberzSOC

Publication detail
← Back to advisories & guidance

ASD’s ACSC, CISA, FBI, and NSA, with the support of International Partners Release Best Practices for Event Logging and Threat Detection ↗ source

August 21, 2024 CISA Alert
Co-sealed by: AIVD, ASD/ACSC, CCCS, CISA, CSA, MIVD, NCSC-NZ, NCSC-UK, NIS, NSA

Summary

Logging priorities for enterprise mobility using mobile computing devices 10 Protecting event logs from unauthorised access, modification and deletion 11 This publication defines a baseline for event logging best practices to mitigate cyber threats. It was developed by the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) in cooperation with the following international partners: Investigation (FBI) and the National Security Agency (NSA) Emergency Response Team Coordination Center (JPCERT/CC) Event logging supports the continued delivery of operations and improves the security and resilience of critical systems by enabling network visibility. This guidance makes recommendations that improve an organisation’s resilience in the current cyber threat environment, with regard for resourcing constraints. The guidance is of moderate technical complexity and assumes a basic understanding of An effective event logging solution aims to: critical software configuration changes are made or new software solutions are deployed employing living off the land (LOTL) techniques or lateral movement post-compromise There are four key factors to consider when pursuing logging best practices: 1. enterprise-approved event logging policy 2. centralised event log access and correlation 3. secure storage and event log integrity 4. detection strategy for relevant threats.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.