Jump to content

Recommended Posts

Posted

Having just seen all the becta bombshell of best /good practice.. i have too realised i need to encrypt usb sitcks and any laptops that go off site...

 

 

my question is more on this guide... http://schools.becta.org.uk/upload-dir/downloads/audit_logging.pdf

 

firstly what do we need to log in reality? it looks to me from reading it.. i basically need all the security logs from my DCs.. i script a log in and out to a SQL DB so this too would be useful (though currently use a stored procedure to remove records older than 32 days so the db didn't grow massive, but holds enough to follow querys up).

 

it looks like i need to keep all my externally available IIS server logs..

 

it looks like the MIS (in our case CMIS) logs too...

 

now the more important question is can we automate this process... the windows security logs just over write them selves after so long... and don't "archive" them selves off..

 

the other thing that looked manualish time consuming is the moving of the logs on to read only media.. the becta report seemed to imply this should be done regularly implying that once a week was poor / high risk.

 

has anyone started to look at this yet?

Posted (edited)

Have a search for data protection and becta on the forums - it comes up a lot.

 

Initial thread: http://www.edugeek.net/forums/school-ict-policies/15430-becta-information-security-guidance-schools-published.html

 

We have a working group sorting this out - me (NM), two governors, deputy head and head of ict.

 

Some of it is merely an extension of what we already do, some of it has an attached time/money/hardware cost.

 

Two things to remember:

 

1) Don't panic.

2) The advice hinges on "reasonableness". When looking at a log ask yourself: "As an outside person, how long would I reasonably expect the school to retain this log?"

 

Windows servers can be configured to log to an external syslog server with minimal effort. Your main issue is getting the logs (or rather a copy of them) into something that can provide decent search functionality so the data is usable.

 

For each device / apps individual logs:

 

What does the log hold?

Where does it hold it?

In what format? (.txt, .evt, binary, gzipped plain text etc)

How long is data kept for before it overwrites? Is this sufficient?

Who has access to the log?

Do we need to retain this log for auditing purposes?

 

Once you have the above info, you can work out the scale of the task.

Edited by pete
  • 2 weeks later...
Posted

Just had a meeting with Splunk's VP for EMEA. One of our technicians is rolling it out for a huge retailer in the UK at the minute and it is a fantastic product.

 

You can use the full version for free with a few caveats but I would definately recommend anyone who doesn't want to trawl through endless management / log consoles trying to find things when you can have a search engine akin to how google searches the web for free!

 

You can download it here; Splunk : Download Splunk 3.4.6

 

It is available for Linux, Mac, Windows (2000-> Vista).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...