36 MAC Pt. 1, R. 6.1
Audit and Accountability
Cite as 36 Miss. Admin. Code Pt. 1, R. 6.1
Audit and Accountability
A. Each agency must create and retain system audit logs and records to the extent needed
to enable the monitoring, analysis, investigation, and reporting of unlawful or
unauthorized system activity.
1. Establish and maintain a process for managing audit logs. This process should
include documented policy which addresses the sensitivity of the agency’s
audit logs, personnel who will retain ownership of audit logs, log handling
procedures, and log disposal requirements. Review and update documentation
annually, or when significant agency changes occur that could impact this
safeguard.
2. Ensure the audit log management process defines the agency’s logging
requirements. At a minimum, address the collection, review, and retention of
audit logs for agency assets.
3. Collect audit logs for all agency assets (especially those processing, storing, or
transmitting sensitive data) as defined in the collection requirements of the
audit log management process.
4. Ensure that all audit logs, if applicable, include event source, date, username,
timestamp, source addresses, destination addresses, and other useful elements
that could assist in a forensic investigation.
5. Ensure that logging destinations maintain adequate storage to comply with the
agency’s audit log management process.
6. Collect DNS query audit logs on agency assets, where appropriate and
supported.
7. Collect URL request audit logs on agency assets, where appropriate and
supported.
8. Collect command-line audit logs, where appropriate and supported. Example
implementations include collecting audit logs from PowerShell®, BASH™,
and remote administrative terminals.
9. Centralize, to the extent possible, audit log collection and retention across
agency assets. This ensures security event alerting for all agency assets can be
easily correlated and analyzed. An example of this would be a central log
server or SIEM that collects and stores all agency asset logs.
10. Ensure that audit logs are maintained based on agency audit log management
processes and include a minimum retention of at least 90 days and a
maximum retention timeline.
11. ITS recommends logging access to sensitive audit log data, including
modification and disposal, to include both the account accessing log data as
well as timestamps.
12. ITS recommends collecting service provider logs, where supported. Examples
include collecting authentication and authorization events, data creation and
disposal events, and user management events.
B. Each agency's use of audit logs must ensure that the actions of individual system
users can be uniquely traced to those users, so they can be held accountable for their
actions.
C. Each agency must conduct reviews of audit logs to detect anomalies or abnormal
events that could indicate a potential threat. Conduct reviews on a weekly, or more
frequent, basis.
D. Each agency must define processes for alerting in the event of an audit logging
failure. These processes should include defined actions to be taken when an alert is
received. Examples of audit log failures includes events such as log disks becoming
full or corrupted. Examples of alerts could be automated emails to be sent to log
management personnel.
E. Each agency must implement a process to review, analyze, and report correlated audit
logs for investigation and response to indications of unlawful, unauthorized,
suspicious, or unusual activity.
F. Each agency must centralize security event alerting across agency assets for log
correlation and analysis.
1. ITS recommends the use of a SIEM, which includes vendor-defined event
correlation alerts. A log analytics platform configured with security-relevant
correlation alerts also satisfies this safeguard.
G. Each agency must configure logging to utilize internal system clocks within each
agency asset to generate time stamps for audit logs.
1. Standardize time synchronization across all agency assets. At least two
synchronized and authoritative time sources should be used in each agency
asset, where supported. Examples of time sources are network time protocol
(NTP) time servers. Agencies on the State network have the option of using
the ITS time servers (tick.its.ms.gov and tock.its.ms.gov).
2. ITS recommends implementing a system capability that compares and
synchronizes internal system clocks with an authoritative source to generate
time stamps for audit records. Examples of time synchronization services and
assets include Windows Time Service (W32Time) and separate, internal
Network Time Protocol (NTP) servers.
H. Each agency must protect audit information and audit logging tools from
unauthorized access, modification, and deletion.
1. ITS recommends encrypting logs for maintaining integrity and confidentiality
of sensitive data.
I. Each agency must limit management of audit logging functionality to a subset of
privileged users. This includes the ability to view, edit, and delete logs, as well as
permissions necessary to change logging configurations.
1. ITS recommends defining and maintaining role-based access control, through
determining and documenting the access rights necessary for management of
audit logging functionality within the agency. Perform access control reviews
of agency assets to validate that all privileges are authorized, on a recurring
schedule at a minimum annually, or more frequently.