Investigations can further assist in gathering vital information about security events, facilitate audit requests, and provide basic information about an environment and the processes and activities within it. SOX investigations can augment a change control process in identifying configuration changes and trying to understand the nature of them to determine whether or not they align with change procedures, along with their implications for SOX compliance. Investigations can also be run to support user access management (provisioning/de-provisioning/termination), privilege user activity, vendor account management, on-boarding of new user access, and other activities. User lists within LogRhythm can align with existing user access provisioning within the company and can be updated at the completion of periodic SOX access reviews.
The SOX: Vulnerability Detail and other investigations related to potential malicious activity cover all log sources in your environment, but specifically require logs from network security systems such as anti-malware systems, security enforcing devices, and vulnerability detection systems. After they are configured correctly, investigations allow IT and security operations to not only deep dive into potential security events, but also to learn more about and continuously improve your overall compliance and cyber security program.
Further, with an emphasis on managing third-party access within your environment, vendor related investigations are applied against all log sources across the environment that administer access to these accounts. The vendor account investigations deep dive into authentication and access activities within the environment to augment related SOX control objectives.
Knowledge Base Content
SOX: Malware Detected Inv
SOX: Vulnerability Detected Inv
SOX: Attack Detected Inv
SOX: Rogue Access Point Inv
SOX: Acct Created, Used, Deleted Inv
SOX: Vendor Acct Authentication Failure Inv
SOX: Vendor Acct Authentication Success Inv
SOX: Vendor Acct Access Failure Inv
SOX: Vendor Acct Access Success Inv
SOX: Vendor Acct Disabled/Enabled Inv
SOX: Vendor Acct UAM Inv
Investigations are used to pull additional details from log sources related to events of interest. The SOX Detail investigations can be used to monitor potential malicious activity to assist in reducing the mean time to detection and to learn about vulnerabilities or exposure points within the environment. IT Security Operations and Management should try to leverage these investigations as a learning mechanism and a means to gather vulnerability data in order to implement controls to reduce the risk exposure.
On the vendor account side, IT Security Operations and Management should use SOX Detail investigations to deep dive into vendor account activity within the environment to better understand ‘normal’ third-party activities and identify when these accounts go beyond their scope of operations within your environment.
These investigations can also be used in access management to validate access within the environment against periodic reviews of third-party accounts.