id: "RA-05(08)" title: "Review Historic Audit Logs" family: "RA" family_name: "Risk Assessment" sort_id: "ra-05.08" priority: "P1" implementation_level: "organization" parent: "RA-05" enhancement: True
Statement
Review historic audit logs to determine if a vulnerability identified in a {{ insert: param, ra-05.08_odp.01 }} has been previously exploited within an {{ insert: param, ra-05.08_odp.02 }}.
Guidance
Reviewing historic audit logs to determine if a recently detected vulnerability in a system has been previously exploited by an adversary can provide important information for forensic analyses. Such analyses can help identify, for example, the extent of a previous intrusion, the trade craft employed during the attack, organizational information exfiltrated or modified, mission or business capabilities affected, and the duration of the attack.
Assessment Objective
historic audit logs are reviewed to determine if a vulnerability identified in a {{ insert: param, ra-05.08_odp.01 }} has been previously exploited within {{ insert: param, ra-05.08_odp.02 }}.
Risk assessment policy
procedures addressing vulnerability scanning
audit logs
records of audit log reviews
vulnerability scanning results
patch and vulnerability management records
system security plan
other relevant documents or records
Organizational personnel with vulnerability scanning responsibilities
organizational personnel with vulnerability scan analysis responsibilities
organizational personnel with audit record review responsibilities
system/network administrators
organizational personnel with security responsibilities
Organizational processes for vulnerability scanning
organizational process for audit record review and response
mechanisms/tools supporting and/or implementing vulnerability scanning
mechanisms supporting and/or implementing audit record review