Security Monitoring Standard
Purpose - Security Monitoring provides a means by which to
confirm that information resource security controls are in place, are
effective and are not being bypassed. One of the benefits of security
monitoring is the early identification of wrongdoing or new security
vulnerabilities. Early detection and monitoring can prevent possible
attacks or minimize their impact on computer systems. Other benefits
include audit compliance, service level monitoring, performance
measuring, limiting liability and capacity planning. This standard
serves as a companion to the Intrusion Detection Standard and provides
for the continuous monitoring that takes place at the system level.
Audience - The UTSA Security Monitoring Standard
applies to all individuals who are responsible for the installation
of new information resources, the operations of existing information
resources and individuals charged with information resource security. |
-
UTSA will use automated tools to provide real-time
notification of detected wrongdoing and vulnerability exploitation.
Where possible, a security baseline will be developed and the tools
will report exceptions. These tools will be deployed by the Office
of Information Technology (OIT) to monitor UTSA computers and devices for:
-
Internet traffic
-
Electronic mail traffic
-
LAN traffic, protocols and device
inventory
-
Operating system security
parameters
-
Rogue access points/devices
-
Installed software on servers and
desktops
-
The following files will be checked for signs of
illicit activity and vulnerability to exploitation at a frequency
determined by risk:
-
Automated intrusion detection
system logs
-
Firewall logs
-
User account logs
-
Network scanning logs
-
System error logs
-
Configuration files
-
Application logs
-
Data backup and recovery logs
-
OITConnect trouble tickets
-
Telephone activity – Call Detail
Reports
-
Network printer and fax logs
-
Assigned individuals will monitor the following
(at least annually):
-
Password strength
-
Unauthorized network devices
-
Unauthorized personal Web
servers
-
Unsecured sharing of devices
-
Unauthorized modem use
-
Operating System and software
licenses
-
For audit purposes, logs will be archived for a
minimum of 90 days.
-
Any security issues discovered will be reported
to the Information Security Officer (ISO) for follow-up investigation.
|
|
|