← Back to advisories & guidance
August 21, 2024
CISA
Alert
Co-sealed by: AIVD, ASD/ACSC, CCCS, CISA, CSA, MIVD, NCSC-NZ, NCSC-UK, NIS, NSA
Summary
Logging priorities for enterprise mobility using mobile computing devices 10 Protecting event logs from unauthorised access, modification and deletion 11 This publication defines a baseline for event logging best practices to mitigate cyber threats. It was developed by the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) in cooperation with the following international partners: Investigation (FBI) and the National Security Agency (NSA) Emergency Response Team Coordination Center (JPCERT/CC) Event logging supports the continued delivery of operations and improves the security and resilience of critical systems by enabling network visibility. This guidance makes recommendations that improve an organisation’s resilience in the current cyber threat environment, with regard for resourcing constraints. The guidance is of moderate technical complexity and assumes a basic understanding of An effective event logging solution aims to: critical software configuration changes are made or new software solutions are deployed employing living off the land (LOTL) techniques or lateral movement post-compromise There are four key factors to consider when pursuing logging best practices: 1. enterprise-approved event logging policy 2. centralised event log access and correlation 3. secure storage and event log integrity 4. detection strategy for relevant threats.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
No CVEs are referenced in this publication.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.