Quantcast
Channel: THWACK: Message List
Viewing all articles
Browse latest Browse all 20396

Re: PCI Compliance - Logging

$
0
0

Sounds like you're looking for a SIEM solution like the Log and Event Manager.

 

Among other things, it would centralize your logs, provide a means for searching and reporting on the logs, provide alerting and scheduled reports generation.  The LEM comes with template rules that are the result of collaboration with customers, auditors and our engineers, and categorized by compliance standards like PCI.  The LEM Reports console has stock reports also categorized by industry and compliance.  All of these things can be customized to suit your business.

 

I would argue with the statement "One thing we must do is turn a ton of logging on our Windows servers."  While I find most people deploy the LEM and find that they need to review their audit policies, there's nothing in the PCI standards that simply says "TURN ON ALL THE THINGS!"  What PCI (and most other compliance standards) want is for you to turn on the right things.  That's a much trickier problem, but a more rewarding solution.  If you simply cranks all the settings to maximum, you'll get a lot of logs, most of which are meaningless noise.  If/when you need to actually find something, you'll be looking for a needle in a field of hay-stacks.  It's a much better plan to tune the auditing to minimize the amount of hay you get, and maximize the needles.


Viewing all articles
Browse latest Browse all 20396

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>