Information Security

profileChipZee
Final_Research_Paper_Sample_Liberty_University_Server_Audit_Policy-1.docx

Z:\RESOURCES\GRAPHICS\Wordmarks\LU_Wordmark_CMYK.JPG

Server Audit Policy

Free Use Disclaimer: This policy was created by or for the Liberty University for the Internet community. All or parts of this policy can be freely used for your organization. There is no prior approval required. If you would like to contribute a new policy or updated version of this policy, please send email to policy-resources@liberty. edu.

Things to Consider: Please consult the Things to Consider FAQ for additional guidelines and suggestions for personalizing the Liberty University policies for your organization.

Last Update Status: Retired

1. Overview

See Purpose.

2. Purpose

The purpose of this policy is to ensure all servers deployed at Liberty University are configured according to the Liberty University security policies. Servers deployed at Liberty University shall be audited at least annually and as prescribed by applicable regulatory compliance.

Audits may be conducted to:

· Ensure integrity, confidentiality and availability of information and resources

· Ensure conformance to Liberty University security policies

3. Scope

This policy covers all servers owned or operated by Liberty University. This policy also covers any server present on Liberty University premises, but which may not be owned or operated by Liberty University.

4. Policy

Liberty University hereby provides its consent to allow <Internal or External Audit Name> to access its servers to the extent necessary to allow <Audit organization> to perform scheduled and ad hoc audits of all servers at Liberty University.

4.1 Specific Concerns

Servers in use for Liberty University support critical business functions and store company sensitive information. Improper configuration of servers could lead to the loss of confidentiality, availability or integrity of these systems.

4.2 Guidelines

Approved and standard configuration templates shall be used when deploying server systems to include:

· All system logs shall be sent to a central log review system

· All Sudo / Administrator actions must be logged

· Use a central patch deployment system

· Host security agent such as antivirus shall be installed and updated

· Network scan to verify only required network ports and network shares are in use

· Verify administrative group membership

· Conduct baselines when systems are deployed and upon significant system changes

· Changes to configuration template shall be coordinated with approval of change control board

4.3 Responsibility

<Internal or External Audit Name> shall conduct audits of all servers owned or operated by Liberty University. Server and application owners are encouraged to also perform this work as needed.

4.4 Relevant Findings

All relevant findings discovered as a result of the audit shall be listed in the Liberty University tracking system to ensure prompt resolution or appropriate mitigating controls.

4.5 Ownership of Audit Report.

All results and findings generated by the <Internal or External Audit Name> Team must be provided to appropriate Liberty University management within one week of project completion. This report will become the property of Liberty University and be considered company confidential.

5. Policy Compliance

5.1 Compliance Measurement

<Internal or External Audit Name> shall never use access required to perform server audits for any other purpose

The Infosec Team will verify compliance to this policy through various methods, including but not limited to, business tool reports, internal and external audits, and feedback to the policy owner.

5.2 Exceptions

Any exception to the policy must be approved by the Infosec Team in advance.

5.3 Non-Compliance

An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.

6 Related Standards, Policies and Processes

None.

7 Definitions and Terms

None.

8 Revision History

Date of Change

Responsible

Summary of Change

Dec 2016

Liberty University Policy Team

Converted format and retired.

Liberty University 2016 – All Rights Reserved Page 3

Liberty University 2016

All Rights Reserved

Page

1

Server Audit

Policy

Free Use Disclaimer:

This policy was created by or for the

Liberty University

for the

Internet community. All or parts of this policy can be freely used for your organization.

There is no prior approval required. If you would like to contribute a new policy or

updated version of this policy, please send email to

policy

-

resources@liberty.

edu

.

Things to Consider:

Please consult the Things to Consider FAQ for additional

guidelines and suggestions for personalizing the

Liberty University

policies

for your

organization.

Last Update

Status:

Retired

1.

Overview

See Purpose.

2.

Purpose

The purpose of this policy is to ensure all servers deployed at

Liberty University

are configured

according to the

Liberty University

security policies. Servers deployed at

Liberty University

shall be audited a

t least annually and as prescribed by applicable regulatory compliance.

Audits may be conducted to:

·

Ensure integrity, confidentiality and availability of information and resources

·

Ensure conformance to

Liberty University

security policies

3.

Scope

This policy covers all servers owned or operated by

Liberty University

. This policy also covers

any server present on

Liberty University

premises, but which may not be owned

or operated by

Liberty University

.

4.

Policy

Liberty University

hereby provides its consent to allow <Internal or External Audit Name> to

access its servers to the extent necessary to allow <Audit organization> to perform scheduled

and ad hoc audits of all servers at

Liberty University

.

4.1

Specific Concerns

Servers in

use for

Liberty University

support critical business functions and store company

sensitive information. Improper configuration of servers could lead to the loss of confidentiality,

availability or integrity of these systems.

4.2

Guidelines

Approved and standa

rd configuration templates shall be used when deploying server systems to

include:

·

All system logs shall be sent to a central log review system

Liberty University 2016 – All Rights Reserved Page 1

Server Audit Policy

Free Use Disclaimer: This policy was created by or for the Liberty University for the

Internet community. All or parts of this policy can be freely used for your organization.

There is no prior approval required. If you would like to contribute a new policy or

updated version of this policy, please send email to [email protected].

Things to Consider: Please consult the Things to Consider FAQ for additional

guidelines and suggestions for personalizing the Liberty University policies for your

organization.

Last Update Status: Retired

1. Overview

See Purpose.

2. Purpose

The purpose of this policy is to ensure all servers deployed at Liberty University are configured

according to the Liberty University security policies. Servers deployed at Liberty University

shall be audited at least annually and as prescribed by applicable regulatory compliance.

Audits may be conducted to:

 Ensure integrity, confidentiality and availability of information and resources

 Ensure conformance to Liberty University security policies

3. Scope

This policy covers all servers owned or operated by Liberty University. This policy also covers

any server present on Liberty University premises, but which may not be owned or operated by

Liberty University.

4. Policy

Liberty University hereby provides its consent to allow <Internal or External Audit Name> to

access its servers to the extent necessary to allow <Audit organization> to perform scheduled

and ad hoc audits of all servers at Liberty University.

4.1 Specific Concerns

Servers in use for Liberty University support critical business functions and store company

sensitive information. Improper configuration of servers could lead to the loss of confidentiality,

availability or integrity of these systems.

4.2 Guidelines

Approved and standard configuration templates shall be used when deploying server systems to

include:

 All system logs shall be sent to a central log review system