n) records of transactions executed by users in applications.
Event logging sets the foundation for automated monitoring systems which are capable of
generating consolidated reports and alerts on system security.
Event logs can contain sensitive data and personally identifiable information. Appropriate
privacy protection measures should be taken.
Where possible, system administrators should not have permission to erase or de-activate logs
of their own activities. (NL ISO/IEC, 2015)
9. Securing Application Services on Public Networks
Information involved in application services passing over public networks should be protected
from fraudulent activity, contract dispute and unauthorized disclosure and modification.
Information security considerations for application services passing over public networks
should include the following:
a) the level of confidence each party requires in each other’s claimed identity, e.g.
through authentication;
b) authorization processes associated with who may approve contents of, issue or sign
key transactional documents;
c) ensuring that communicating partners are fully informed of their authorizations for
provision or use of the service;
d) determining and meeting requirements for confidentiality, integrity, proof of
dispatch and receipt of key;
e) documents and the non-repudiation of contracts, e.g. associated with tendering and
contract processes;
f) the level of trust required in the integrity of key documents;
g) the protection requirements of any confidential information;
h) the confidentiality and integrity of any order transactions, payment information,
delivery address details and confirmation of receipts;
i) the degree of verification appropriate to verify payment information supplied by a
customer;
j) selecting the most appropriate settlement form of payment to guard against fraud;
k) the level of protection required to maintain the confidentiality and integrity of order
information;
l) avoidance of loss or duplication of transaction information;
m) liability associated with any fraudulent transactions;
n) insurance requirements.
Many of the above considerations can be addressed by the application of cryptographic
controls, taking into account compliance with legal requirements.
Lebanese National Security Policy Guidelines v1.7
Page
49 |