UNCLASSIFIED 5.11 Protective Monitoring Protective monitoring comprises of technical and procedural measures geared at detecting and stopping attempts to exploit information system vulnerabilities. Organisations should take a risk-based approach to selecting the level of protective monitoring undertaken. Thus, the level of protective monitoring should match business requirements, exposure to threats and risks and the business impact of security breaches. The mandated minimum security outcomes outlined below would help create an effective protective monitoring regime. IS10 – All organisations must implement measures to detect, and tie to users, unauthorised information processing activities. As a minimum requirement, organisations must: (a) define a monitoring strategy; (b) adopt an accounting and audit policy; (c) produce, and preserve for an agreed time, audit logs recording user activities, exceptions, faults and security events; (d) establish procedures for reviewing monitoring results; (e) train staff to interpret monitoring results; (f) protect audit and logging facilities and log data; and, (g) align protective monitoring with incident management and HR policies. To achieve the security outcomes mandated above, organisations must:  Define and adopt a protective monitoring strategy that defines the objectives, approaches and resources required to support consistent organisation-wide accounting, audit and monitoring activities;  Have in place an accounting and audit policy that complies with business requirements for real-time security accounting and audit. The policy shall help developers and product teams ensure that technical solutions consist of suitable accounting and audit points. In addition, it should help information assurance teams to verify the extent to which the implemented accounting and audit features comply with NISF security accreditation requirements;  Ensure that the network security architecture contains suitable features to identify, record, alert and generate security audit reports;  Ensure that accounting activities match the level of logging for each security classification. IT teams must not deviate from the accounting requirements before presenting a risk assessment and convincing management that the new level of logging adequately assures the security of business activities;  Standardise accounting and audit log data to ease correlation in accordance with ISO/IEC 27002;  Have in place effective procedures to review recorded logs and alerts to help identify and hold to account those who misuse information assets;  Hire and maintain a competent team to administer the technological solutions and supporting infrastructures that collect, store and log suspicious events; 33

Select target paragraph3