Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 8.1
Related:
Clause 8
|
Detection in Depth
|
2-1 SPE 7
|
FR 6
|
Packet Capture Analysis (PCAP)
Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10
Clause 8 pages: Cl. 8 | 8.1 Log auditing | 8.2 Malicious code | 8.3 IDS | 8.4 Vulnerability scanners | 8.5 Forensics | 8.6 Host configuration | 8.7 Software management
Log auditing utilities collect, retain and review records of system and security events. Active log management can flag an attack or policy violation in progress and help locate it. Teaching note: a SIEM (Security Information and Event Management) platform is the usual modern aggregator for these functions; the TR describes the capability, not the product class.
Undetected misuse, lack of accountability, and inability to reconstruct an incident. Logs are evidence of integrity as well as of intrusion.
Host and application logs, firewall and authentication logs, forwarded to a collector with time synchronisation. Review may be manual, scheduled or correlated.
Plan logging at project inception, or retrofit promptly. There is enough value in a tangible integrity record to warrant use even on plants that will not staff a 24-hour SOC.