id: "RA-05(08)" title: "Review Historic Audit Logs" family: "RA" family_name: "Risk Assessment" sort_id: "ra-05.08" priority: "P1" implementation_level: "organization" parent: "RA-05" enhancement: True


Statement

Review historic audit logs to determine if a vulnerability identified in a {{ insert: param, ra-05.08_odp.01 }} has been previously exploited within an {{ insert: param, ra-05.08_odp.02 }}.

Guidance

Reviewing historic audit logs to determine if a recently detected vulnerability in a system has been previously exploited by an adversary can provide important information for forensic analyses. Such analyses can help identify, for example, the extent of a previous intrusion, the trade craft employed during the attack, organizational information exfiltrated or modified, mission or business capabilities affected, and the duration of the attack.

Assessment Objective

historic audit logs are reviewed to determine if a vulnerability identified in a {{ insert: param, ra-05.08_odp.01 }} has been previously exploited within {{ insert: param, ra-05.08_odp.02 }}.

Risk assessment policy

procedures addressing vulnerability scanning

audit logs

records of audit log reviews

vulnerability scanning results

patch and vulnerability management records

system security plan

other relevant documents or records

Organizational personnel with vulnerability scanning responsibilities

organizational personnel with vulnerability scan analysis responsibilities

organizational personnel with audit record review responsibilities

system/network administrators

organizational personnel with security responsibilities

Organizational processes for vulnerability scanning

organizational process for audit record review and response

mechanisms/tools supporting and/or implementing vulnerability scanning

mechanisms supporting and/or implementing audit record review