Educause Security Discussion mailing list archives

Re: University-level Log Policy


From: Matthew Gracie <graciem () CANISIUS EDU>
Date: Tue, 5 Jun 2007 11:47:09 -0400

Greg Vickers wrote:
Hi all,

DISCLAIMER: I have not looked anywhere else for this information yet, so
feel free to point out the obvious to me :)

I am about to draft a Log Policy for QUT, it will be reviewed by the IT
Security Manager and the Information Technology Services Director and
will be put forward at a suitable governance level.

I was wondering what log policies exist and are already in use at other
Educause Universities? And would it be possible to see what your log
policy is if it exists?

I'm looking for examples of system and service log policy, i.e. Windows
Server, Redhat Server, Apache, etc etc.

Thanks,

One of the things that we did when looking at log retention policy was
attempt to figure out how long logs are actually useful for us, from a
system administration and forensic point of view.

For example, if you never need logs from a particular system or class of
systems that are more than sixty days old, then the policy should
reflect that. Even if a policy says logs should be scrapped after thirty
days, if your admins need them for longer than that, the policy is just
going to get ignored.

Just my two cents,

--Matt

--
Matt Gracie                         (716) 888-2403
Information Security Administrator  graciem () canisius edu
Canisius College ITS                425531N / 0785109W
http://www2.canisius.edu/~graciem/graciem_public_key.gpg        

Current thread: