Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 28 of 35

6. Security events should be logged and monitored

Keeping your eyes open for possible attacker activity.

Logging and auditing of events that indicate changes in the secure operation of a device can help highlight possible attacker activity, provide early warning of compromise and offer a foundation for analysis in response an any security incidents.

Effective logging will not always deter an adversary, but as long as appropriate monitoring and auditing of logs is in place, it does increase the likelihood that their activity will be exposed. This, in turn may decrease their potential appetite for attack. Logging should be informed by the threat that a product is likely to be exposed to.

Security logs should be treated like other sensitive data, and protected accordingly. Compromise of logs can enable adversaries to gain insights into security configurations, but also enable malicious activity to go undetected.

Example defensive measures

  • Logs are most useful when their purpose is clearly defined. You should choose the events you log based on the threats that might apply to a device, and consider categorising events by level of importance, based on the level of action to be taken in response to them.
  • Access to management functions that allow modification of the security configuration of a device may be of particular concern. For these, or other events critical to security, you should consider triggering alerts for more immediate attention.
  • Access to logs should be a privileged function, limited to those in administrator roles, and disabled by default. Logs should be protected through mechanisms to detect unexpected modification and alerting in response to unauthorised changes.
  • Logs should persist for the lifetime of the product. This may mean you need to periodically back them up, or export them securely. Remote logging can help avoid on-device storage limitations over long periods of time. Developers should consider how to enable modelling and measurement of typical logging behaviour to help users choose appropriate storage and handling.
  • Logs are only useful if there is an appropriate strategy for monitoring and auditing, to identify abnormal behaviour. Structured logs make auditing easier, whether this is manual or automated. Where auditing is manual, critical events should be highlighted and easy to identify, reducing cognitive burden on the auditor.
  • Auditing is most effective if suspicious behaviour patterns can readily be recognised. For automated monitoring, models of typical suspicious behaviour are needed. A system-wide monitoring and auditing system may be helpful, and all monitoring systems should provide meaningful and actionable alerting in a way that is useful to the user or system owner.

Published

Reviewed

Version

1.0