Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GWS.COMMONCONTROLS.14.1v0.1 implementation steps incomplete #240

Open
adhilto opened this issue Mar 27, 2024 · 6 comments · May be fixed by #263
Open

GWS.COMMONCONTROLS.14.1v0.1 implementation steps incomplete #240

adhilto opened this issue Mar 27, 2024 · 6 comments · May be fixed by #263

Comments

@adhilto
Copy link
Collaborator

adhilto commented Mar 27, 2024

The baseline requirement:
image

What the implementation steps say to do:
image

This will send logs to GCP. But the requirement is to send the logs to "the agency's centralized SEIM," which seems like would require an additional step, depending on what the agency is using as their SEIM.

@jkaufman-mitre
Copy link
Collaborator

Will assess with the team and make needed changes.

@jkaufman-mitre
Copy link
Collaborator

Will discuss with @tmcomeau to determined what action should be taken.

@jkaufman-mitre
Copy link
Collaborator

After discussing this issue with @tmcomeau, @lrsmitre, @prodjom, and @mdueltgen we believe changes need to be made. We propose the following options:

Option 1: Leave the policy as is and add an implementation step saying to follow the steps in the GCP link I found for sending logs to a SIEM.

Option 2: Change the policy to make the requirement to have the logs sent to GCP and in the not say that the policy is to facilitate the sending of logs to SIEM.

@adhilto and @buidav Which option do you think would be the best as we cannot include specific implementation on how to connect to a SIEM as it could be different for each agency.

@buidav
Copy link
Collaborator

buidav commented Apr 10, 2024

@adhilto and @buidav Which option do you think would be the best as we cannot include specific implementation on how to connect to a SIEM as it could be different for each agency.

There was a similar discussion for M365 AAD 4.1 with Ted and the M365 team. Instead of having instructions of how to send the logs to any one place, the instructions were left to be generic with a note on the policy pointing to CLAW. Note that this policy we still have some back and forth with, as it is the least prescriptive policy in AAD. Rope in Ted if you want to hear his thoughts on it.

Instructions:
Follow the configuration instructions unique to the products and integration patterns at your organization to send the security logs to the security operations center for monitoring.

Note: Agencies can benefit from security detection capabilities offered by the CISA Cloud Log Aggregation Warehouse (CLAW) system. Agencies are urged to send the logs to CLAW. Contact CISA at [[email protected]](mailto:[email protected]) to request integration instructions.

@jkaufman-mitre
Copy link
Collaborator

@buidav Ok, thank you! I will use the instructions you provided.

@jkaufman-mitre jkaufman-mitre linked a pull request Apr 10, 2024 that will close this issue
14 tasks
@jkaufman-mitre
Copy link
Collaborator

Pull request has been created.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants