Archive for September, 2008

List of Log Report that required by SOX 404

List of Log Report that required by SOX 404
- User Logon/Logoff Report : Sec 302 (a)(4)(C) and (D) - log-in/log-out monitoring
- Logon failure report
- Audit Log Access report
- Object Access report
- System Event report
- Account Mgmt report : sec 302 (a)(6)
- Audit policy changes : sec 302 (a)(5)
- User/Application/Directory or file access : sec 302 […]

Popularity: 48% [?]

Naming Standard for Log Management for SOX

List of naming standard sample for SOX Compliance:
Annual 3rd Party Internal and External Vulnerability Assessment Scan Log
Annual Enterprise Network Architecture & Design Review Log
Annual Firewall System Restore Log
Annual Email System Restore Log
Annual Windows Print & File Server System Restore Log
Daily Anti-Virus Exceptions Log
Daily Email Back-up Log
Daily Windows Print & File Server Back-up Log
Inventory of Hardware, […]

Popularity: 41% [?]

Log Management and SOX Requirement?

Do SOX 404 require us to create a good and comprehensive Log Management Tools? there are many discussion about that. But the main point is that the Log Management (LM) comprises an approach to dealing with large volumes of computer-generated log messages (also known as audit records, audit trails, event-logs, etc). LM covers log collection, […]

Popularity: 43% [?]

Federal standards for internal controls

The OMB provides guidelines in management oversight. “To ensure senior management involvement, many agencies have established their own senior management council, often chaired by the agency” lead management official, to address management accountability and related issues within the broader context of agency operations.”Relevant issues for such a council include ensuring the agency” commitment to an […]

Popularity: 38% [?]