36 MAC Pt. 1, R. 6.1

Audit and Accountability

Year: 2026Length: 795 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 6.1

Audit and Accountability A. Each agency must create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. 1. Establish and maintain a process for managing audit logs. This process should include documented policy which addresses the sensitivity of the agency’s audit logs, personnel who will retain ownership of audit logs, log handling procedures, and log disposal requirements. Review and update documentation annually, or when significant agency changes occur that could impact this safeguard. 2. Ensure the audit log management process defines the agency’s logging requirements. At a minimum, address the collection, review, and retention of audit logs for agency assets. 3. Collect audit logs for all agency assets (especially those processing, storing, or transmitting sensitive data) as defined in the collection requirements of the audit log management process. 4. Ensure that all audit logs, if applicable, include event source, date, username, timestamp, source addresses, destination addresses, and other useful elements that could assist in a forensic investigation. 5. Ensure that logging destinations maintain adequate storage to comply with the agency’s audit log management process. 6. Collect DNS query audit logs on agency assets, where appropriate and supported. 7. Collect URL request audit logs on agency assets, where appropriate and supported. 8. Collect command-line audit logs, where appropriate and supported. Example implementations include collecting audit logs from PowerShell®, BASH™, and remote administrative terminals. 9. Centralize, to the extent possible, audit log collection and retention across agency assets. This ensures security event alerting for all agency assets can be easily correlated and analyzed. An example of this would be a central log server or SIEM that collects and stores all agency asset logs. 10. Ensure that audit logs are maintained based on agency audit log management processes and include a minimum retention of at least 90 days and a maximum retention timeline. 11. ITS recommends logging access to sensitive audit log data, including modification and disposal, to include both the account accessing log data as well as timestamps. 12. ITS recommends collecting service provider logs, where supported. Examples include collecting authentication and authorization events, data creation and disposal events, and user management events. B. Each agency's use of audit logs must ensure that the actions of individual system users can be uniquely traced to those users, so they can be held accountable for their actions. C. Each agency must conduct reviews of audit logs to detect anomalies or abnormal events that could indicate a potential threat. Conduct reviews on a weekly, or more frequent, basis. D. Each agency must define processes for alerting in the event of an audit logging failure. These processes should include defined actions to be taken when an alert is received. Examples of audit log failures includes events such as log disks becoming full or corrupted. Examples of alerts could be automated emails to be sent to log management personnel. E. Each agency must implement a process to review, analyze, and report correlated audit logs for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. F. Each agency must centralize security event alerting across agency assets for log correlation and analysis. 1. ITS recommends the use of a SIEM, which includes vendor-defined event correlation alerts. A log analytics platform configured with security-relevant correlation alerts also satisfies this safeguard. G. Each agency must configure logging to utilize internal system clocks within each agency asset to generate time stamps for audit logs. 1. Standardize time synchronization across all agency assets. At least two synchronized and authoritative time sources should be used in each agency asset, where supported. Examples of time sources are network time protocol (NTP) time servers. Agencies on the State network have the option of using the ITS time servers (tick.its.ms.gov and tock.its.ms.gov). 2. ITS recommends implementing a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records. Examples of time synchronization services and assets include Windows Time Service (W32Time) and separate, internal Network Time Protocol (NTP) servers. H. Each agency must protect audit information and audit logging tools from unauthorized access, modification, and deletion. 1. ITS recommends encrypting logs for maintaining integrity and confidentiality of sensitive data. I. Each agency must limit management of audit logging functionality to a subset of privileged users. This includes the ability to view, edit, and delete logs, as well as permissions necessary to change logging configurations. 1. ITS recommends defining and maintaining role-based access control, through determining and documenting the access rights necessary for management of audit logging functionality within the agency. Perform access control reviews of agency assets to validate that all privileges are authorized, on a recurring schedule at a minimum annually, or more frequently.
36 MAC Pt. 1, R. 6.1: Audit and Accountability | Justis AI