19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 5.9 Logging at the Server<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrator<br />

<strong>The</strong> logging possible on the network server should be activated to a sensible<br />

degree. <strong>The</strong> Network Administrator must review the network server log files<br />

at regular intervals. All security-relevant events should be logged. In this<br />

context, the following occurrences are of particular interest:<br />

- entry of an incorrect password for a user ID through to blocking of the user<br />

ID when the maximum permitted number of unsuccessful attempts has<br />

been reached,<br />

- attempts to gain unauthorised access,<br />

- power failure,<br />

- data on network utilisation and network overload.<br />

How many other events are logged will depend to a certain extent on the<br />

protection requirements of the <strong>IT</strong> systems concerned. <strong>The</strong> greater the<br />

protection requirement, the more information should be logged.<br />

As log files can become very long over time, the intervals at which they are<br />

evaluated should kept short. To enable appropriate analysis of the data, every<br />

protocol entry should include the user ID or process number, terminal device<br />

ID, date and time.<br />

Additional controls:<br />

- Who analyses the log files and at what intervals?<br />

- Are the evaluations documented?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!