EBA欧洲银行-Annex-5-Standard-on-Logging-and-Monitoring_17页_318kb
报告摘要
European Commission Information System Security Policy: Standard on Logging and Monitoring
Core Content Overview
This document outlines the European Commission's Standard on Logging and Monitoring, adopted in 2010 under Commission Decision C(2006) 3602. It establishes mandatory logging and monitoring procedures for all computer systems used by the Commission, including servers, workstations, mobile devices, and network equipment. The standard aims to ensure a consistent minimum level of logging and monitoring while avoiding excessive administrative burden.
Main Objectives
- To provide mandatory instructions for logging and monitoring procedures across all types of computer systems that can generate information security-related log events.
- To ensure that logs are secure, reliable, and usable for auditing, forensic analysis, and incident detection.
- To maintain compliance with data protection regulations and other legal requirements.
- To support system availability, integrity, and confidentiality through effective logging and monitoring.
Scope
The standard applies to all computer systems used by the European Commission, including:
- Servers
- Workstations
- Portable PCs
- PDAs
- Smartphones
- Storage devices
- Network equipment
It also covers non-personal devices such as application servers, firewalls, and intrusion detection systems.
Threats Covered
The standard addresses a range of information security threats, including:
- Loss of power supply
- Telecommunication equipment failure
- Tampering with hardware or software
- Equipment failure or malfunction
- Saturation of information systems
- Data corruption or illegal processing
- Unauthorized use or abuse of rights
- Denial of actions
These threats are aligned with the Standard on Risk Management and are relevant to the Commission's overall security posture.
Logging Requirements
General Logging
All devices must log the following events:
- Successful and failed logon attempts
- Logout events
- Alerts from the access control system
- Activation and deactivation of protection systems
- Events raised by protection systems
- Initialization, modification, or deletion of audit trails
- User account creation, modification, or deletion
Additional Logging for Non-Personal Devices
- Starting/stopping processes
- System configuration changes
- Use of privileges
- Errors and exceptions
- Alerts from environmental changes (e.g., high temperature)
Specific Function Logging
| Device Type | Required Logging |
|---|---|
| Network firewalls | All authentication requests, all VPN session requests, all packets denied by rules, all successful packets destined for the firewall |
| Personal firewalls | Network traffic as defined by the system owner, administrative logins, configuration changes, firewall service start-up/shutdown |
| Intrusion Detection / Prevention Systems | Information security events defined during device configuration |
| Authentication servers | Authentication requests with usernames and originating applications/servers |
| Proxy servers | Proxy requests with results (accepted/rejected + reason) |
| Anti-malware software | Virus definitions and updates, manual scan launches and results, malware incidents |
| Remote access software | Remote user logins/logouts, user access token registration/modification/deletion |
| Vulnerability management software | Scans for updates, successful or failed installation of updates |
| Application software | Changes to sensitive application data |
Monitoring System Use
Monitoring is essential for detecting and responding to threats. Key monitoring systems include:
- Firewalls (network and host-based)
- Gateways to other networks
- Intrusion Detection / Prevention Systems
- Authentication servers
Monitoring must include:
- Unauthorized access attempts
- System alerts or failures
- Changes to security settings
Alerts should be automatically sent to system administrators and analyzed for incident management. Regular reviews and adjustments are necessary to avoid false positives or negatives.
Protection of Log Information
Log information must be protected against tampering and unauthorized access. Key requirements include:
- Log retention of at least six months
- Log protection to ensure only authorized administrators have access
- Clock synchronization to maintain accurate timestamps in logs
- Backup of critical log files to secure, remote locations
Clock Synchronisation
System clocks must be regularly synchronized with an accurate time source, especially across the Commission's processing platforms. Key rules include:
- Clocks must be set to the local time zone and adjusted for daylight savings
- User devices (e.g., PCs, PDAs) should be set to their home time zone
- Synchronization should occur at log-on/log-off for user devices and periodically for servers and network devices
- Use of secure NTP protocols to prevent attacks using false time packets
Roles and Responsibilities
- System Owners: Define events to be logged and ensure compliance with logging policies.
- System Managers: Operate and manage logging and monitoring solutions and ensure IT service providers comply.
- IT Service Providers: Operate logging and monitoring solutions in accordance with the standard.
Key References
- Commission Decision C(2006) 3602 (adopted 16 August 2006)
- Regulation (EC) No 45/2001 on Data Protection
- Standard on Risk Management
- Standard on Information Systems Security Incident Management
- International standards: ISO/IEC 27001, ISO/IEC 17799, NIST SP 800-92
Terminology
- Alert: A message indicating a significant event requiring attention.
- Audit: A documented process to evaluate the performance of operational procedures.
- Event: An identifiable action recorded in logs.
- Log: A record of events, either a single entry or the entire logging process.
- Log Entry: A record of a single event.
- Logfile: A file containing log entries.
- Monitoring: Proactive checking for information security incidents.
- UTC: Coordinated Universal Time, used as a reference for time synchronization.
Conclusion
This standard ensures consistent, secure, and effective logging and monitoring practices across the European Commission's information systems. It emphasizes the importance of log retention, protection, and synchronization, and outlines the roles and responsibilities of various stakeholders. The standard is aligned with international norms and legal requirements, and is a mandatory part of the Commission's security framework.
试读结束,高清完整版pdf/doc/ppt,请点下载