CCF – Reports and Reporting Packages


Reports

Reports

Applicable Frameworks

Data Source

Intelligent Indexing

Classification

Log Sources

CCF: Access Failure Summary

NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

No

Audit

All Available Log Sources

CCF: Access Success Summary

NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

No

Audit

All Available Log Sources

CCF: Account Deleted Summary

NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

No

Audit

All Available Log Sources

CCF: Account Disabled Summary

NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

LogMart

No

Audit

All Available Log Sources

CCF: Account Enabled Summary

NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

Yes

Audit

All Available Log Sources

CCF: Account Modification Summary

NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

No

Audit

All Available Log Sources

CCF: Applications Accessed By User Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Data Processor(s)

No

Operations

All Available Log Sources

CCF: Audit Log Summary

UAE-NESA, NIST 800-53, NIST 800- 171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

Yes

Audit

All Available Log Sources

CCF: Auth Failure Summary

NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

No

Audit

All Available Log Sources

CCF: Auth Success Summary

NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

No

Audit

All Available Log Sources

CCF: Backup Activity Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Data Processor(s)

No

Operations

All Available Log Sources

CCF: Compromises Detected Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

LogMart

Yes

Security

All Available Log Sources

CCF: Config/Policy Change Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

LogMart

Yes

Audit

All Available Log Sources

CCF: Critical Environment Error Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

Yes

Operations

All Available Log Sources

CCF: GeoIP Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS,  CJIS, State DPLs

Platform Manager

Yes

Security

All Available Log Sources

CCF: Host Access Granted And Revoked Detail

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Data Processor(s)

Yes

Audit

All Available Log Sources

CCF: LogRhythm Data Loss Defender Log Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

LogMart

Yes

Operations

All Available Log Sources

CCF: Malware Detected Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

Yes

Security

All Available Log Sources

CCF: Object Access Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Data Processor(s)

No

Audit

All Available Log Sources

CCF: Patch Activity Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Data Processor(s)

Yes

Operations

All Available Log Sources

CCF: Physical Access Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

Yes

Audit

All Available Log Sources

CCF: Priv Account Management Activity Summary

UAE-NESA, NIST 800-53, NIST 800- 171, NIST CSF, NY DFS, CJIS,  State DPLs

Data Processor(s)

Yes

Audit

All Available Log Sources

CCF: Priv Authentication Activity Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

Yes

Audit

All Available Log Sources

CCF: Rogue Access Point Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

Yes

Security

All Available Log Sources

CCF: Signature Activity Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

LogMart

Yes

Operations

All Available Log Sources

CCF: Social Media Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

No

Audit

All Available Log Sources

CCF: Suspected Wireless Attack Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

Yes

Security

All Available Log Sources

CCF: Term Account Activity Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Data Processor(s)

Yes

Audit

All Available Log Sources

CCF: Time Sync Error Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

Yes

Operations

All Available Log Sources

CCF: Top Suspicious Users

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Data Processor(s)

Yes

Security

All Available Log Sources

CCF: Unknown User Account Detail

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Data Processor(s)

Yes

Security

All Available Log Sources

CCF: Use Of Non- Encrypted Protocols Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

LogMart

Yes

Audit

All Available Log Sources

CCF: User Misuse Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

No

Security

All Available Log Sources

CCF: User Object Access Summary

GDPR, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Data Processor(s)

Yes

Audit

All Available Log Sources

CCF: User Priv Escalation (SU & SUDO) Summary

UAE-NESA, NIST 800-53, NIST 800- 171, NIST CSF, NY DFS, CJIS, State DPLs

Data Processor(s)

Yes

Audit

All Available Log Sources

CCF: User Priv Escalation (Windows) Summary

UAE-NESA, NIST 800-53, NIST 800- 171, NIST CSF, NY DFS, CJIS,  State DPLs

Platform Manager

Yes

Audit

All Available Log Sources

CCF: Vulnerability Detected Summary

GDPR, UAE-NESA, NIST 800-53, NIST 800-171, NIST CSF, NY DFS, CJIS, State DPLs

Platform Manager

Yes

Security

All Available Log Sources

Reporting Packages

Report Package Name

Report Package Description

Report Package ID

CCF: Daily IT Operations Reporting

Package

This Reporting Package is a template to deliver pertinent content for IT Operations on a daily basis.

89

CCF: Daily IT Security Reporting Package

This Reporting Package is a template to deliver pertinent content for IT Security on a daily basis.

90

CCF: Executive Reporting Package

This reporting package is a template to deliver pertinent content for Executives on a monthly basis.

87

CCF: Weekly Audit Reporting Package

This Reporting Package is a template to deliver pertinent content for Internal and/or External Audit groups on a weekly basis.

88

Customize a Report Package by Cloning

The CCF Report Packages provide default report selections for their intended audiences. To fully customize a Report Package, clone the package rather than editing the default package directly.

Use the following workflow:

  1. Open the Report Center.

  2. Select the Report Packages tab.

  3. Select the check box for the report package you want to customize and use.

  4. Right-click the selected report package, and then select Clone.

  5. Customize the package settings and report selections. Select Next to move through each configuration section.

  6. When the Save option becomes available, review the configuration and save the cloned Report Package.

  7. After the cloned Report Package is saved, configure a schedule if the package should run automatically.

Report results depend on the log sources, scope, lists, entities, and other configuration available in the environment. Review and customize the cloned package for the organization before scheduling it for production use.

Default Reports Included in Each CCF Report Package

The following reports are selected by default in the updated CCF Report Packages.

CCF: Daily IT Operations Report Package (ID 89)

Report Name

Report ID

CCF: Backup Activity Summary

2062

CCF: Config/Policy Change Summary

2049

CCF: Critical Environment Error Summary

2050

CCF: Patch Activity Summary

2052

CCF: Daily IT Security Report Package (ID 90)

Report Name

Report ID

CCF: Auth Failure Summary

2088

CCF: Auth Success Summary

2090

CCF: Compromises Detected Summary

2064

CCF: Malware Detected Summary

2051

 CCF: Executive Report Package (ID 87)

Report Name

Report ID

CCF: Top Suspicious Users

2059

CCF: User Misuse Summary

2061

CCF: Vulnerability Detected Summary

2058

 CCF: Weekly Audit Report Package (ID 88)

Report Name

Report ID

CCF: Access Failure Summary

2089

CCF: Access Success Summary

2091

CCF: Account Deleted Summary

2086

CCF: Account Disabled Summary

2084

CCF: Account Enabled Summary

2085

CCF: Account Modification Summary

2092

CCF: Audit Log Summary

2076

CCF: Term Account Activity Summary

2087