<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Logged &#187; Compliance</title>
	<atom:link href="http://www.syslog.org/logged/category/compliance/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.syslog.org/logged</link>
	<description>Event and Log Management</description>
	<lastBuildDate>Sun, 25 Jul 2010 21:40:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Designing A Log and Event Monitoring Program</title>
		<link>http://www.syslog.org/logged/designing-a-log-and-event-monitoring-program/</link>
		<comments>http://www.syslog.org/logged/designing-a-log-and-event-monitoring-program/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 02:25:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[logging]]></category>

		<guid isPermaLink="false">http://www.syslog.org/logged/?p=133</guid>
		<description><![CDATA[Ultimately, as with all IT security programs, log monitoring programs are designed to address risks to data confidentiality, integrity and availability.  Risks come in many types: Hardware failure System compromise User error Rogue administrator An organization&#8217;s program around log &#38; event monitoring needs to be based on the specific risks that exist in that organization.  [...]<p>Post from: <a href="http://www.syslog.org/logged">Logged - Log Management Blog</a><br/><br/><a href="http://www.syslog.org/logged/designing-a-log-and-event-monitoring-program/">Designing A Log and Event Monitoring Program</a></p>
]]></description>
		<wfw:commentRss>http://www.syslog.org/logged/designing-a-log-and-event-monitoring-program/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Configuring SUDO for Effective Activity Monitoring Via Syslog</title>
		<link>http://www.syslog.org/logged/configuring-sudo-for-effective-activity-monitoring-via-syslog/</link>
		<comments>http://www.syslog.org/logged/configuring-sudo-for-effective-activity-monitoring-via-syslog/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 22:26:43 +0000</pubDate>
		<dc:creator>mutex</dc:creator>
				<category><![CDATA[Accountability]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[SUDO]]></category>

		<guid isPermaLink="false">http://www.syslog.org/logged/?p=123</guid>
		<description><![CDATA[I have discussed in previous posts the importance of administrators using SUDO to provide individual accountability.  SUDO provides command-by-command accounting of actions performed by administrators, with logs sent as standard syslog events looking like this: Feb  4 19:23:23 bsd sudo:    jerry : TTY=pts/0 ; PWD=/usr/home/jerry ; USER=root ; COMMAND=/bin/ps -x Feb  4 19:23:34 bsd sudo:    [...]<p>Post from: <a href="http://www.syslog.org/logged">Logged - Log Management Blog</a><br/><br/><a href="http://www.syslog.org/logged/configuring-sudo-for-effective-activity-monitoring-via-syslog/">Configuring SUDO for Effective Activity Monitoring Via Syslog</a></p>
]]></description>
		<wfw:commentRss>http://www.syslog.org/logged/configuring-sudo-for-effective-activity-monitoring-via-syslog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Building A Program To Manage And Monitor Administrators</title>
		<link>http://www.syslog.org/logged/program-to-manage-and-monitor-administrators/</link>
		<comments>http://www.syslog.org/logged/program-to-manage-and-monitor-administrators/#comments</comments>
		<pubDate>Sun, 24 Jan 2010 21:46:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[SUDO]]></category>

		<guid isPermaLink="false">http://www.syslog.org/logged/?p=111</guid>
		<description><![CDATA[Monitoring the activities of privileged users or server administrators is becoming a common requirement in many organizations for a few reasons: Compliance with legal or regulatory requirements, such as PCI, HIPAA, etc Performing outsourcing services to clients who require controls to prevent the service provider&#8217;s employees from causing harm to the client. A recent experience [...]<p>Post from: <a href="http://www.syslog.org/logged">Logged - Log Management Blog</a><br/><br/><a href="http://www.syslog.org/logged/program-to-manage-and-monitor-administrators/">Building A Program To Manage And Monitor Administrators</a></p>
]]></description>
		<wfw:commentRss>http://www.syslog.org/logged/program-to-manage-and-monitor-administrators/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Using Syslog Logs For Validation of Security Policy Compliance</title>
		<link>http://www.syslog.org/logged/using-syslog-logs-for-validation-of-security-policy-compliance/</link>
		<comments>http://www.syslog.org/logged/using-syslog-logs-for-validation-of-security-policy-compliance/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 21:49:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.syslog.org/logged/?p=100</guid>
		<description><![CDATA[In a previous post, I wrote about the general use of syslog logs as a method of ensuring compliance with policy.  This is a specific example of how one might use syslog to do that. As IT operations mature, particularly in regulated environments, it is not uncommon for an organization&#8217;s security policy to require controls [...]<p>Post from: <a href="http://www.syslog.org/logged">Logged - Log Management Blog</a><br/><br/><a href="http://www.syslog.org/logged/using-syslog-logs-for-validation-of-security-policy-compliance/">Using Syslog Logs For Validation of Security Policy Compliance</a></p>
]]></description>
		<wfw:commentRss>http://www.syslog.org/logged/using-syslog-logs-for-validation-of-security-policy-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What To Look For In A Compliance Report From Logs</title>
		<link>http://www.syslog.org/logged/what-to-look-for-in-a-compliance-report-from-logs/</link>
		<comments>http://www.syslog.org/logged/what-to-look-for-in-a-compliance-report-from-logs/#comments</comments>
		<pubDate>Tue, 21 Apr 2009 21:10:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[FFIEC]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[SOX]]></category>

		<guid isPermaLink="false">http://www.syslog.org/logged/?p=48</guid>
		<description><![CDATA[Reports from system logs for compliance generally have the same basic requirements regardless of the standard being measured &#8211; whether PCI, SOX or FFIEC.  There are some foundational requirements for compliance reporting of logs to be considered effective: The data/time are synchronized throughout the environment.  This is vital to be able to correlate events between [...]<p>Post from: <a href="http://www.syslog.org/logged">Logged - Log Management Blog</a><br/><br/><a href="http://www.syslog.org/logged/what-to-look-for-in-a-compliance-report-from-logs/">What To Look For In A Compliance Report From Logs</a></p>
]]></description>
		<wfw:commentRss>http://www.syslog.org/logged/what-to-look-for-in-a-compliance-report-from-logs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why Using A Log Management Service Might Be Right For You</title>
		<link>http://www.syslog.org/logged/why-using-a-log-management-service-might-be-right-for-you/</link>
		<comments>http://www.syslog.org/logged/why-using-a-log-management-service-might-be-right-for-you/#comments</comments>
		<pubDate>Sun, 19 Apr 2009 04:09:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Log Management Service]]></category>
		<category><![CDATA[Outsourcing]]></category>

		<guid isPermaLink="false">http://www.syslog.org/logged/?p=34</guid>
		<description><![CDATA[There are a growing number of Managed Security Service Providers (MSSP&#8217;s), such as IBM and Symantec, and Verisign, and other companies, such as Savvis, offering an outsourced service to collect and retain system logs, generally called a log management service (LMS).  The initial instinct for many would be to reject such a crazy thought as [...]<p>Post from: <a href="http://www.syslog.org/logged">Logged - Log Management Blog</a><br/><br/><a href="http://www.syslog.org/logged/why-using-a-log-management-service-might-be-right-for-you/">Why Using A Log Management Service Might Be Right For You</a></p>
]]></description>
		<wfw:commentRss>http://www.syslog.org/logged/why-using-a-log-management-service-might-be-right-for-you/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Creative Use of System Logs to Ensure Policy Compliance</title>
		<link>http://www.syslog.org/logged/creative-use-of-system-logs-to-ensure-policy-compliance/</link>
		<comments>http://www.syslog.org/logged/creative-use-of-system-logs-to-ensure-policy-compliance/#comments</comments>
		<pubDate>Sat, 11 Apr 2009 03:51:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Log Management]]></category>
		<category><![CDATA[Policy]]></category>

		<guid isPermaLink="false">http://www.syslog.org/logged/?p=3</guid>
		<description><![CDATA[Organizations that need to minimize the risks associated with managing technology infrastructure implement robust policies on access management, change management and the like. Having robust and well understood policies is important and expected of most organizations.  However, organizations such as the FFIEC expects that financial institutions apply detective controls to affirmatively identify policy violations where [...]<p>Post from: <a href="http://www.syslog.org/logged">Logged - Log Management Blog</a><br/><br/><a href="http://www.syslog.org/logged/creative-use-of-system-logs-to-ensure-policy-compliance/">Creative Use of System Logs to Ensure Policy Compliance</a></p>
]]></description>
		<wfw:commentRss>http://www.syslog.org/logged/creative-use-of-system-logs-to-ensure-policy-compliance/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
