Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Please check my understanding of security auditing and Event logging 1

Status
Not open for further replies.

DanielUK

IS-IT--Management
Jul 22, 2003
343
GB
Hi,

To comply with PCI DSS I am purchasing something like EventAnalyzer to collate my logs.

However, before I do that I need to make sure all my machines are set up to log correctly.

I have the following in my domain:

1. An SBS 2003 server
2. 4 Windows 2000 servers (2 of them global catalogs)
3. 12 Win XP Pro workstations
4. 3 x Windows 2000 workstations

Am I right in thinking I need to do the following:

a) enable local event auditing for all servers/workstations via Local Security settings/Audit Policy

b) on my Domain Controllers, also enable Audiditing in Domain Controller Security Policy

c) within Active Directory, set auditing via group policy for the domain or OU

d) if I then want to track access to a certain file or folder then I have to do this locally via Explorer and setting the audit settings on the Security tab.

Is all this correct?

Thanks

Dan
 
I'm not sure what the PCI requirements are, but that sounds about right to me from the auditing I've had to set up before. You may have an extra step in there with the GP, but depending on the PCI needs, that may be right.

I wouldn't have commented, given that I don't have much to add, but since no one else did, I figured I'd at least give some feedback.

Dave Shackelford
Shackelford Consulting
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top