Event logs are the basic text of what happens in your corporate systems. So why do so many companies ignore them?
We love this blog post by Constantine von Hoffman. In fact, we had a vibrant discussion about this very topic internally yesterday. We might take a bit of exception to the assertion that log review is “cheap and easy.” I mean, if it were so cheap and easy, wouldn’t most organizations be doing it?
What we find in healthcare is that the logs are so voluminous because there are so many disparate systems and devices in play. Most organizations report to us that it is simply impossible, based on the way they are resourced, to have any kind of meaningful log review and log management program. Further, it is hard to translate for the “non-techies” in risk management how this process is vital to enterprise risk management. So what happens?
Higher performing organizations are collecting and archiving the logs from most of their systems so that they have them “handy” in the event that they need them to support an investigation or incident response. Maybe a few of those high performers review logs for their high value/high risk systems routinely. The highest performers have dedicated the resources required – through the internal investment in tools and/or staff or via outsourcing to an MSSP – to implement an operationally-relevant and compliance-aware log management program.
That said, more often than not, we encounter organizations that don’t know what they are collecting, how they have auditing capabilities enabled in their systems, and have no log review or log management program in place.
The operational relevance is obvious, but in healthcare, we have that little regulation better know as the HIPAA Security Rule that specifically culls out “user activity monitoring” as an implementation specification. An effective log management program goes a long way to meeting this compliance requirement.
Based on the recent summary report from the first 20 OCR audits, what was the single greatest deficiency or area of non-compliance vis-a-vis the HIPAA Security Rule? You guessed it (and if you are a regular reader, you’ve read it here before) … User Activity Monitoring.
In our discussions with OCR, it is clear that this facet of an organization’s information security program is going to continue to be carefully reviewed and scrutinized. So, whether via a formal audit, breach or complaint investigation, be prepared to have your log management program under the microscope.
It is our belief, from our 10+ years of experience and service to the healthcare industry, that few organizations are on a trajectory for IT security staffing to effectively implement an organic log management program. After all, your core business is healthcare and your team should be focused on the enablement of care. As we have mused in previous posts, maybe this is the time for organizations to make an active choice to engage security experts to support their security functional requirements, particularly those that really lend themselves well to outsourcing, like log monitoring and management.
Of course, at CynergisTek, we have a solution for this and we would be happy to talk with you more about what we are doing and how we have chosen to help our clients address this gap. But what we really hope this post compels, is a change in the conversation that you are having internally. Does it really make sense to build an information security empire within your healthcare organization or does it make better sense to be a healthcare center of excellence that practices good security? That is a strategy and tactical discussion that we would love to support you with if our experience can be of help.
Make it a good day!