OMB Mandates Agency Log Standardization to Improve Security

Industries Tim Frank

T he Office of Management and Budget’s memo mandates a maturity model for event log management, sets agency implementation requirements, and establishes government-wide responsibilities. Fortunately, Splunk solutions can help agencies comply with the new mandates.

As I wrote in a recent blog post, Biden Administration Executive Order Reinforces Log Standardization is Key to Security, in May 2021, the Biden Administration issued its much-anticipated Executive Order aimed at improving the cyber posture of the country. The Fact Sheet accompanying its release appropriately noted that “[r]ecent cybersecurity incidents such as SolarWinds, Microsoft Exchange, and the Colonial Pipeline incident are a sobering reminder that U.S. public and private sector entities increasingly face sophisticated malicious cyber activity from both nation-state actors and cyber criminals.” Since the Order’s release in May, we have not seen any slowing down in terms of the sophistication and frequency of incidents.

On August 27, OMB issued an implementation memo specific to the Order’s directions in Section 8 regarding log management. The “Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incidents” memo is broken down into three key sections:

Maturity Model for Event Log Management

The Maturity Model sets distinct logging tiers with the stated purpose of helping agencies to prioritize certain aspects of implementation to reach full memo compliance over time. These tiers include “not effective,” “basic,” “intermediate,” and “advanced” categorization.

Agency Implementation Requirements

In section 2 agencies are directed to immediately begin implementing the memo’s requirements, with several milestones that must be met within a specific timeframe. For example, agencies have 60 calendar days to submit any identified resource gaps and funding plans to meet the memo’s requirements. Agencies must also reach the intermediate level under the maturity model within 18 months.

Government-Wide Responsibilities

In the third section on Government-Wide Responsibilities, specific tasks are given to both CISA and the Commerce Department. For CISA, they have been tasked to send teams to individual agencies to advise on their current logging capabilities and to work with the FBI to develop tools to assess logging maturity. The Commerce Department is tasked with updating NIST’s Guide to Computer Security Log Management to account for these new requirements.

MISC

The memo also includes a series of appendices covering things like centralized access and definitions. Appendix C, in particular, provides specific logging technical details that agencies are being required to follow. In this appendix, OMB breaks down log categories and corresponding required data, format, criticality, and specific retention periods.

How Splunk Can Help

Splunk can assist agencies in implementing these requirements in numerous ways, including:

This article was co-authored by Drew Church, Security Consulting Sales Engineer at Splunk, and Ryan Kovar, Distinguished Strategist at Splunk.

Related Articles

AI + Quantum in Manufacturing: Bold Predictions, Reality Checks and Real-Life Examples
Industries
8 Minute Read

AI + Quantum in Manufacturing: Bold Predictions, Reality Checks and Real-Life Examples

Meet John, the plant manager, together with Caesar, the manufacturing AI robot, Milo, the quantum watchdog with superposition capabilities, and the rest of the AI + Quantum manufacturing crew of the factory of the future. Read on about bold predictions, reality checks at Hannover Messe and real-life Splunk / Cisco examples of AI + Quantum in manufacturing.
DoD’s Cyber Posture: A Focus on Automation
Industries
2 Minute Read

DoD’s Cyber Posture: A Focus on Automation

The importance of the security of the Department of Defense’s (DoD’s) networks is no secret (well, of course a lot of it is secret!). This is evidenced by the Department’s IT/Cybersecurity budget request that annually tops $40 billion dollars. Last year’s IT and Cyberspace Activities Budget Overview perhaps said it best: “Successful mission execution is contingent on a seamless, secure infrastructure that transforms data into actionable information and ensures dependable mission execution in the face of the persistent cyber threat.”
Bridging the Cyber Confidence Gap: Digital Resilience in the Public Sector
Industries
2 Minute Read

Bridging the Cyber Confidence Gap: Digital Resilience in the Public Sector

Mick Baccio shares the findings of Splunk's report – conducted in collaboration with Foundry – on bridging the resilience gap across public and private sectors.