Project

General

Profile

Actions

Task Tracker #188

open
RA NK

System Gap-23 OMS has not determined what needs to be monitored and measured (including information security processes and controls), methods for monitoring, measurement, analysis, and evaluation, when the monitoring and measuring shall be performed...

Task Tracker #188: System Gap-23 OMS has not determined what needs to be monitored and measured (including information security processes and controls), methods for monitoring, measurement, analysis, and evaluation, when the monitoring and measuring shall be performed...

Added by Redmine Admin 7 months ago. Updated 27 days ago.

Status:
In Progress
Priority:
Medium
Start date:
03/11/2026
Due date:
% Done:

30%

Estimated time:

Description

  1. OMS has not determined what needs to be monitored and measured (including information security processes and controls), methods for monitoring, measurement, analysis, and evaluation, when the monitoring and measuring shall be performed, who shall monitor and measure, or when the results from monitoring and measurement shall be analyzed and evaluated. As a result, there is no documentation pertaining this.

OMS has not defined what security activities should be monitored, how they should be measured, or who is responsible.

Consolidated Security Monitoring and Measurement Scope

This ticket is the implementation record for the monitoring and measurement gap and must support the 4C penetration-test remediation programme.

Required Monitoring

  • Define security events, controls, metrics, data sources, owners, thresholds and review frequency.
  • Centralise and protect relevant firewall, reverse-proxy, DNS, authentication, operating-system, application, database, mail and cloud-platform logs.
  • Monitor public service exposure, rejected connections, privileged access, abnormal authentication, suspicious DNS/egress, application errors, upload failures, cache anomalies and security-control failures.
  • Create alerts and tested playbooks for exposed services, suspected injection, cache poisoning, malicious uploads, abnormal DNS/egress, credential misuse and backup/restore abuse.
  • Define retention, access control, integrity protection, time synchronisation and privacy requirements for logs.
  • Record alert ownership, escalation, incident-ticket creation, evidence preservation and periodic effectiveness testing.
  • Produce a monthly monitoring report linked to #179 and the applicable MANCO risk review.

Acceptance Criteria

  • The monitoring catalogue, metrics, owners, thresholds and review calendar are approved.
  • Critical log sources are onboarded and their collection and retention are verified.
  • Alerts are tested using authorised simulations and produce the expected escalation and evidence.
  • Monitoring gaps and failed alerts have owners and target dates.
  • Monthly monitoring evidence and risk-report links are retained in controlled SharePoint storage.

Files

OMS_188_Monitoring_Catalogue.xlsx (16.1 KB) OMS_188_Monitoring_Catalogue.xlsx Ntokozo Khanyile, 07/28/2026 08:16 AM

RA Updated by Redmine Admin 7 months ago Actions #1

  • Subject changed from System Gap to System Gap-23 OMS has not determined what needs to be monitored and measured (including information security processes and controls), methods for monitoring, measurement, analysis, and evaluation, when the monitoring and measuring shall be performed...

LM Updated by Liberty Mutabvuri 2 months ago Actions #2

  • Description updated (diff)
  • Assignee set to Ntokozo Khanyile

Assigned to Ntokozo Khanyile and expanded as the security monitoring, measurement, alerting and tested-playbook implementation ticket for the 4C remediation programme.

LM Updated by Liberty Mutabvuri 2 months ago Actions #3

4C implementation links: #491 is the remediation umbrella; #492–#495 require monitoring and tested alerts appropriate to each workstream.

NK Updated by Ntokozo Khanyile 2 months ago Actions #4

A draft Security Monitoring & Measurement Catalogue has been produced (see attached OMS_188_Monitoring_Catalogue.xlsx), covering:

Monitoring Catalogue – 12 security events/controls in scope (exposure, rejected connections, privileged access, abnormal auth, DNS/egress, app errors, uploads, cache anomalies, control failures, plus OS/DB/mail), each with a proposed metric, data source, owner, threshold and review frequency.
Log Handling Standard – proposed retention, access control, integrity protection, time-sync and POPIA-relevant privacy requirements for all 9 required log sources.
Alert & Playbook Register – the 7 alert scenarios named in this ticket, with trigger conditions, owners, escalation paths, and incident-ticket/evidence-preservation process.

All rows are marked "Draft – Pending Confirmation" and Test Status "Not Tested". This is a starting proposal for the Security Lead to review and ratify, not a ratified catalogue.

This gap is not yet closed. No log sources have actually been onboarded and no alerts have been built or tested — that work requires Coolify/network access and is tracked as Steps 3–4 in the Implementation Runbook attached to #179.

Leaving open until log sources are confirmed onboarded and alerts are tested with evidence.

NK Updated by Ntokozo Khanyile 27 days ago Actions #5

Progress Update - 2026-09-03

System Gap-23: Monitoring & Measurement

✅ COMPLETED:

Monitoring Catalogue (12 Metrics):
✅ M-001: Public service exposure - defined
✅ M-002: Rejected connections - defined
✅ M-003: Privileged access - defined
✅ M-004: Abnormal authentication - defined
✅ M-005: Suspicious DNS / egress - defined
✅ M-006: Application errors - defined
✅ M-007: Upload failures / malicious uploads - defined
✅ M-008: Cache anomalies - defined
✅ M-009: Security-control failures - defined
✅ M-010: OS-level integrity - defined
✅ M-011: Database access anomalies - defined
✅ M-012: Mail security events - defined

Log Handling Standard (9 Log Sources):
✅ Firewall - retention, access, integrity defined
✅ Reverse Proxy - retention, access, integrity defined
✅ DNS - retention, access, integrity defined
✅ Authentication (IdP/MFA) - retention, access, integrity defined
✅ Operating System - retention, access, integrity defined
✅ Application - retention, access, integrity defined
✅ Database - retention, access, integrity defined
✅ Mail - retention, access, integrity defined
✅ Cloud Platform (Coolify/Cloud) - retention, access, integrity defined

Alert & Playbook Register (7 Scenarios):
✅ Exposed service detected - defined
✅ Suspected injection attack - defined
✅ Cache poisoning indicator - defined
✅ Malicious upload blocked - defined
✅ Abnormal DNS / egress - defined
✅ Credential misuse - defined
✅ Backup / restore abuse - defined

Templates & Processes:
✅ Monthly monitoring report template created
✅ Alert ownership and escalation defined
✅ Incident ticket creation defined
✅ Evidence preservation defined

Evidence Location:

  • Monitoring Catalogue: OMS_188_Monitoring_Catalogue.xlsx

⏳ PENDING (Requires System Access):

Log Source Onboarding (Requires Coolify/Cloud Access):
⏳ Firewall logs onboarded
⏳ Reverse proxy logs onboarded
⏳ DNS logs onboarded
⏳ Authentication logs onboarded
⏳ OS logs onboarded
⏳ Application logs onboarded
⏳ Database logs onboarded
⏳ Mail logs onboarded
⏳ Cloud platform logs onboarded

Alert Implementation (Requires Log Sources):
⏳ 7 alerts built and configured
⏳ Authorised simulation testing
⏳ Escalation testing
⏳ Evidence preservation testing

Acceptance Criteria Status:

  • ✅ Monitoring catalogue approved (documentation complete)
  • ✅ Log handling standard defined
  • ✅ Alert scenarios defined
  • ⏳ Critical log sources onboarded (requires system access)
  • ⏳ Alerts tested (requires log sources)
  • ⏳ Monthly monitoring evidence retained (pending implementation)

% Complete: 40%

Next Steps:

  1. Schedule session with Infrastructure Lead for log onboarding
  2. Obtain Coolify/Cloud console access
  3. Build and test alerts
  4. Run first monthly monitoring report
Actions

Also available in: PDF Atom