Project

General

Profile

Task Tracker #188

Updated by Liberty Mutabvuri 14 days ago

23. OMS has not determined what needs to be monitored and measured (including information security processes and controls), methods for monitoring, measurement, analysis, and evaluation, when the monitoring and measuring shall be performed, who shall monitor and measure, or when the results from monitoring and measurement shall be analyzed and evaluated. As a result, there is no documentation pertaining this. 

 OMS has not defined what security activities should be monitored, how they should be measured, or who is responsible. 

 # Consolidated Security Monitoring and Measurement Scope 

 This ticket is the implementation record for the monitoring and measurement gap and must support the 4C penetration-test remediation programme. 

 ## Required Monitoring 

 - Define security events, controls, metrics, data sources, owners, thresholds and review frequency. 
 - Centralise and protect relevant firewall, reverse-proxy, DNS, authentication, operating-system, application, database, mail and cloud-platform logs. 
 - Monitor public service exposure, rejected connections, privileged access, abnormal authentication, suspicious DNS/egress, application errors, upload failures, cache anomalies and security-control failures. 
 - Create alerts and tested playbooks for exposed services, suspected injection, cache poisoning, malicious uploads, abnormal DNS/egress, credential misuse and backup/restore abuse. 
 - Define retention, access control, integrity protection, time synchronisation and privacy requirements for logs. 
 - Record alert ownership, escalation, incident-ticket creation, evidence preservation and periodic effectiveness testing. 
 - Produce a monthly monitoring report linked to #179 and the applicable MANCO risk review. 

 ## Acceptance Criteria 

 - The monitoring catalogue, metrics, owners, thresholds and review calendar are approved. 
 - Critical log sources are onboarded and their collection and retention are verified. 
 - Alerts are tested using authorised simulations and produce the expected escalation and evidence. 
 - Monitoring gaps and failed alerts have owners and target dates. 
 - Monthly monitoring evidence and risk-report links are retained in controlled SharePoint storage. 

Back