-
Notifications
You must be signed in to change notification settings - Fork 11
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
GWS.COMMONCONTROLS.14.1v0.1 implementation steps incomplete #240
Comments
Will assess with the team and make needed changes. |
Will discuss with @tmcomeau to determined what action should be taken. |
After discussing this issue with @tmcomeau, @lrsmitre, @prodjom, and @mdueltgen we believe changes need to be made. We propose the following options: Option 1: Leave the policy as is and add an implementation step saying to follow the steps in the GCP link I found for sending logs to a SIEM. Option 2: Change the policy to make the requirement to have the logs sent to GCP and in the not say that the policy is to facilitate the sending of logs to SIEM. @adhilto and @buidav Which option do you think would be the best as we cannot include specific implementation on how to connect to a SIEM as it could be different for each agency. |
There was a similar discussion for M365 AAD 4.1 with Ted and the M365 team. Instead of having instructions of how to send the logs to any one place, the instructions were left to be generic with a note on the policy pointing to CLAW. Note that this policy we still have some back and forth with, as it is the least prescriptive policy in AAD. Rope in Ted if you want to hear his thoughts on it. Instructions:
|
@buidav Ok, thank you! I will use the instructions you provided. |
Pull request has been created. |
The baseline requirement:
What the implementation steps say to do:
This will send logs to GCP. But the requirement is to send the logs to "the agency's centralized SEIM," which seems like would require an additional step, depending on what the agency is using as their SEIM.
The text was updated successfully, but these errors were encountered: