Castleforce IT Security Team

A.10.10 Monitoring

Objective: To detect unauthorized information processing activities.

A.10.10.1 Audit logging

Audit logs recording user activities, exceptions, and information security events shall be produced and kept for an agreed period to assist in future investigations and access control monitoring.

A.10.10.2 Monitoring system use

Procedures for monitoring use of information processing facilities shall be established and the results of the monitoring activities reviewed regularly.

A.10.10.3 Protection of log information

Logging facilities and log information shall be protected against tampering and unauthorized access.

A.10.10.4 Administrator and operator logs

System administrator and system operator activities shall be logged.

A.10.10.5 Fault logging

Faults shall be logged, analyzed, and appropriate action taken.

A.10.10.6 Clock synchronization

The clocks of all relevant information processing systems within an organization or security domain shall be synchronized with an agreed accurate time source.

Log Management Appliances

LogRhythm integrated-enterprise-class log management-log analysis and event management solution LogRhythm is an enterprise-class application that seamlessly combines Log & Event Management, File Integrity Monitoring and Endpoint Monitoring & Control into a single integrated solution.  It is highly reliable, cost effective and easily scalable across any size enterprise.  With LogRhythm, you can invest in a single solution to address needs and challenges throughout your organization, whether they are related to compliance, security or IT operations.

For more details on LogRhythm Single Integrated Appliances

LogLogic log management and database activity monitoring LogLogic Open Log Management Collect, normalize, index, store, and search log data automatically with our easy-to-deploy appliances or hosted solutions. Rapidly drill down into log details and create detailed reports with our built-in templates. All LogLogic appliances are run on hardened linux appliances that are designed to offer full log processing and archive based on the amount of Event Per Second (EPS) design. 

For more details on LogLogic Log Management Appliances



Contact Castleforce for help with ISO27001 

Log Management Software

Assuria Auditor measures, manages and enforces security policies and Log Manager is designed to meet the requirements of enterprise wide management of audit logs generated by systems, devices and applications Assuria Log Manager (ALM) has achieved CESG CCTM approval and securely collects and manages audit logs to comply with regulations. The small footprint ALM agents are available for Windows, UNIX and Linux servers, databases, applications, network devices, firewalls, routers, access control systems and many more. Collection from new log sources can be added via agent plug-ins. Collected logs are stored in their original format in a standard file / folder structure with log data integrity ensured through digital signatures and cryptographic hashes.

For more details on Assuria Log Manager

Log Management SaaS

SureCloud SureGuard Vulnerability Management SureCloud offer Log Management for network devices and servers in an managed service model via their SureGuard vulnerability manager portal.

For more details on the SureCloud SureGuard Log Management service