System integrity verification and integrity checking
Log analysis
White Listing
Black Listing
Data Loss Prevention (DLP)
10.2.
Used to detect changes to critical system
components such as files, directories or services.
These changes may alert a system administrator to
unauthorized changes that could signify an attack
on the system and inadvertent system changes that
render the system open to attack.
Involves collecting and analyzing event logs using
pattern recognition to detect anomalous activities
Lists the authorized activities and applications and
permits their usage
Lists the non‐authorized activities and applications
and prevents their usage
Data Egress monitoring and control
Reporting Information Security Incidents
Objective:
Mandatory Control 1:
Mandatory Control 2:
Mandatory Control 3:
Mandatory Control 4:
Recommended Control 1:
Recommended Control 2:
Reporting information security incidents, assists in maintaining
an accurate threat environment picture for government systems
Agencies must direct personnel to report information security
incidents to an ITSM as soon as possible after the information
security incident is discovered in accordance with agency
procedures
The ITSM must keep the CISO fully informed of information
security incidents within an agency
The Agency ITSM must report significant information security
incidents to the BCC
Agencies that outsource their information technology services and
functions must ensure that the service provider consults with the
agency when an information security incident occurs
Agencies should:
encourage personnel to note and report any observed or
suspected security weaknesses in, or threats to, systems or
services
establish and follow procedures for reporting software
malfunctions
put mechanisms in place to enable the types, volumes and
costs of information security incidents and malfunctions to
be quantified and monitored
deal with the violation of agency information security
policies and procedures by personnel through a formal
disciplinary process
Agencies should formally report information security incidents
43