Task Tracker #188
openSystem Gap-23 OMS has not determined what needs to be monitored and measured (including information security processes and controls), methods for monitoring, measurement, analysis, and evaluation, when the monitoring and measuring shall be performed...
30%
Description
- OMS has not determined what needs to be monitored and measured (including information security processes and controls), methods for monitoring, measurement, analysis, and evaluation, when the monitoring and measuring shall be performed, who shall monitor and measure, or when the results from monitoring and measurement shall be analyzed and evaluated. As a result, there is no documentation pertaining this.
OMS has not defined what security activities should be monitored, how they should be measured, or who is responsible.
Consolidated Security Monitoring and Measurement Scope¶
This ticket is the implementation record for the monitoring and measurement gap and must support the 4C penetration-test remediation programme.
Required Monitoring¶
- Define security events, controls, metrics, data sources, owners, thresholds and review frequency.
- Centralise and protect relevant firewall, reverse-proxy, DNS, authentication, operating-system, application, database, mail and cloud-platform logs.
- Monitor public service exposure, rejected connections, privileged access, abnormal authentication, suspicious DNS/egress, application errors, upload failures, cache anomalies and security-control failures.
- Create alerts and tested playbooks for exposed services, suspected injection, cache poisoning, malicious uploads, abnormal DNS/egress, credential misuse and backup/restore abuse.
- Define retention, access control, integrity protection, time synchronisation and privacy requirements for logs.
- Record alert ownership, escalation, incident-ticket creation, evidence preservation and periodic effectiveness testing.
- Produce a monthly monitoring report linked to #179 and the applicable MANCO risk review.
Acceptance Criteria¶
- The monitoring catalogue, metrics, owners, thresholds and review calendar are approved.
- Critical log sources are onboarded and their collection and retention are verified.
- Alerts are tested using authorised simulations and produce the expected escalation and evidence.
- Monitoring gaps and failed alerts have owners and target dates.
- Monthly monitoring evidence and risk-report links are retained in controlled SharePoint storage.
Files
RA Updated by Redmine Admin 5 months ago
- Subject changed from System Gap to System Gap-23 OMS has not determined what needs to be monitored and measured (including information security processes and controls), methods for monitoring, measurement, analysis, and evaluation, when the monitoring and measuring shall be performed...
LM Updated by Liberty Mutabvuri 14 days ago
- Description updated (diff)
- Assignee set to Ntokozo Khanyile
Assigned to Ntokozo Khanyile and expanded as the security monitoring, measurement, alerting and tested-playbook implementation ticket for the 4C remediation programme.
LM Updated by Liberty Mutabvuri 14 days ago
4C implementation links: #491 is the remediation umbrella; #492–#495 require monitoring and tested alerts appropriate to each workstream.
NK Updated by Ntokozo Khanyile 4 days ago
- File OMS_188_Monitoring_Catalogue.xlsx OMS_188_Monitoring_Catalogue.xlsx added
- Status changed from New to In Progress
- % Done changed from 0 to 30
A draft Security Monitoring & Measurement Catalogue has been produced (see attached OMS_188_Monitoring_Catalogue.xlsx), covering:
Monitoring Catalogue – 12 security events/controls in scope (exposure, rejected connections, privileged access, abnormal auth, DNS/egress, app errors, uploads, cache anomalies, control failures, plus OS/DB/mail), each with a proposed metric, data source, owner, threshold and review frequency.
Log Handling Standard – proposed retention, access control, integrity protection, time-sync and POPIA-relevant privacy requirements for all 9 required log sources.
Alert & Playbook Register – the 7 alert scenarios named in this ticket, with trigger conditions, owners, escalation paths, and incident-ticket/evidence-preservation process.
All rows are marked "Draft – Pending Confirmation" and Test Status "Not Tested". This is a starting proposal for the Security Lead to review and ratify, not a ratified catalogue.
This gap is not yet closed. No log sources have actually been onboarded and no alerts have been built or tested — that work requires Coolify/network access and is tracked as Steps 3–4 in the Implementation Runbook attached to #179.
Leaving open until log sources are confirmed onboarded and alerts are tested with evidence.