Log Security
3 slides · 1 min read · Domain 6
When needing logs for evidence, organizations can obtain copies of original, centralized, and interpreted log data if the copying and interpretation processes' accuracy are questioned.
This could cause a variety of impacts, including allowing malicious activities to go unnoticed and manipulating evidence to conceal the identity of a malicious party. For example, many rootkits are specifically designed to alter logs to remove any evidence of the rootkits' installation or execution.
Log Security
Log security protects stored records, controls access, detects tampering, and preserves integrity.
ISO 27001:2022 emphasizes the importance of logging, protecting, and analyzing events to enhance security, detect breaches, and support investigations.
Security controls are put in place to ensure that log data is protected from being tampered with or altered by unauthorized individuals. Organizations are legally required to store their log data for a specific period of time, as dictated by laws, regulations, and internal governance standards.
The organization's policies and procedures should also address the preservation of original logs. Many organizations send copies of network traffic logs to centralized devices, as well as use tools that analyze and interpret network traffic.
Retaining logs for evidence may involve the use of different forms of storage and different processes, such as additional restrictions on access to the records.
Logs need to be protected from breaches of their confidentiality and integrity.
For example, logs might intentionally or inadvertently capture sensitive information such as users' passwords and the content of emails. This raises security and privacy concerns involving both those who review the logs and others who might access them through authorized or unauthorized means.
Logs that are secured improperly in storage or in transit might also be susceptible to intentional and unintentional alteration and destruction.
