Opinion: Making the case for an audit standard
DOD example shows importance of cooperation
March 14, 2006 12:00 PM ETEditors note: As NIST gathers this spring to ponder a common event-logging format, the pressure on vendors to hew to at least basic common event-logging and audit structures makes itself plain throughout the industry. Mary Ann Davidson, chief security officer at Oracle Corp., shares her thoughts on whats at stake.
When it comes to IT security, it often seems that vendors would rather build and sell a point solution to customers -- solving just one problem in a proprietary way -- than play nicely with other vendors to improve the security landscape for all. This is painfully apparent in the area of event logging and auditing (or eventing).
Theres an old maxim, For want of a nail, the shoe was lost; for want of a shoe, the horse was lost, culminating in the kingdom was lost. The lack of common event logging and auditing requirements -- and a common format for that data when collected -- may well result in our collective network kingdoms being indefensible. Furthermore, a kingdom that cant be defended can indeed be lost.
Nowhere is the need for a common requirement more apparent than in the U.S. Department of Defense. The DODs Global Information Grid (GIG) program seeks to connect physically separate networks (for classified, unclassified and war-fighter information) so that selected intelligence information can flow in real time to a combatant accessing information wirelessly in a battle zone.
However, removing the physical barriers to network connectedness heightens the risk profile for the collective DOD network. The network itself becomes the battlefield, since the DODs entire war-fighting capability is based on an IT backbone. Just as combatants need situational awareness on the physical battlefield Where are my forces? Where are the enemys forces? they will need situational awareness for the IT backbone on which their capabilities depend. Opposing forces might not be able to muster superiority of arms, but theyre likely to find it worthwhile to attack the network, thereby disrupting the DODs ability to wage war.
The DODs prospects for situational awareness of that IT backbone are severely hampered by the fact that the off-the-shelf software on which much of its systems depend commercial operating systems, routers, firewalls, databases, directories and applications often have little or no auditing. Moreover, what auditing data exists is not expressed in a common format. While third-party software can parse and redact multiple log file formats, consolidate them and connect the dots to show related activity, their job would be markedly simpler if at least some core data were both collected and expressed in the same way across products. (And of course, if no data exists, these products cannot correlate data at all.) The value these vendors add is largely not in their ability to perform the network security equivalent of translating Coptic, Koinic Greek and Hebrew into English, but in being able to correlate information, which is a data warehousing problem. Translation in that situation is just the cost of correlation.
Additional Resources


White Papers & Webcasts
Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
IDC White Paper: CCM for IT Compliance and Risk Management
Learn from industry analysts how IT organizations are using configuration management to meet compliance requirements and instill best practices. Find out how these...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
Keep it Clean: Maintaining the Integrity of your CMDB through Change Detection
Learn how configuration drift can challenge configuration management database (CMDB) integrity and how a configuration audit tool and an effective change management process...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
The Tripwire HIPAA Solution: Meeting the Security Standards Set Forth in Section 164
HIPAA requires businesses that handle personal health information (PHI) to set up strong controls to ensure the security and integrity of that information....
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Configuration Assessment: Choosing the Right Solution
Configuration assessment lets businesses proactively secure their IT infrastructure and achieve compliance with important industry standards and regulations. Learn why configuration assessment is...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
