UNCLASSIFIED
5.11
Protective Monitoring
Protective monitoring comprises of technical and procedural measures geared at
detecting and stopping attempts to exploit information system vulnerabilities.
Organisations should take a risk-based approach to selecting the level of
protective monitoring undertaken. Thus, the level of protective monitoring should
match business requirements, exposure to threats and risks and the business
impact of security breaches. The mandated minimum security outcomes outlined
below would help create an effective protective monitoring regime.
IS10 – All organisations must implement measures to detect, and tie to users,
unauthorised information processing activities. As a minimum requirement,
organisations must: (a) define a monitoring strategy; (b) adopt an accounting
and audit policy; (c) produce, and preserve for an agreed time, audit logs
recording user activities, exceptions, faults and security events; (d) establish
procedures for reviewing monitoring results; (e) train staff to interpret
monitoring results; (f) protect audit and logging facilities and log data; and, (g)
align protective monitoring with incident management and HR policies.
To achieve the security outcomes mandated above, organisations must:
Define and adopt a protective monitoring strategy that defines the objectives,
approaches and resources required to support consistent organisation-wide
accounting, audit and monitoring activities;
Have in place an accounting and audit policy that complies with business
requirements for real-time security accounting and audit. The policy shall
help developers and product teams ensure that technical solutions consist of
suitable accounting and audit points. In addition, it should help information
assurance teams to verify the extent to which the implemented accounting
and audit features comply with NISF security accreditation requirements;
Ensure that the network security architecture contains suitable features to
identify, record, alert and generate security audit reports;
Ensure that accounting activities match the level of logging for each security
classification. IT teams must not deviate from the accounting requirements
before presenting a risk assessment and convincing management that the
new level of logging adequately assures the security of business activities;
Standardise accounting and audit log data to ease correlation in accordance
with ISO/IEC 27002;
Have in place effective procedures to review recorded logs and alerts to help
identify and hold to account those who misuse information assets;
Hire and maintain a competent team to administer the technological solutions
and supporting infrastructures that collect, store and log suspicious events;
33