Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Implement executive order M-21-31 #6070

Open
hannes-ucsc opened this issue Mar 19, 2024 · 7 comments
Open

Implement executive order M-21-31 #6070

hannes-ucsc opened this issue Mar 19, 2024 · 7 comments
Assignees
Labels
+ [priority] High compliance [subject] Information and software security demo [process] To be demonstrated at the end of the sprint orange [process] Done by the Azul team POAM 2024

Comments

@hannes-ucsc
Copy link
Member

hannes-ucsc commented Mar 19, 2024

FedRAMP SSP rev 5 Template for Moderate system says

AU-11 Audit Record Retention (L)(M)(H)
Retain audit records for [FedRAMP Assignment: a time period in compliance with M-21-31] to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements.

  	AU-11 Additional FedRAMP Requirements and Guidance:
  	Guidance: The service provider is encouraged to align with M-21-31 where possible

Requirement: The service provider retains audit records on-line for at least ninety days and further preserves audit records off-line for a period that is in accordance with NARA requirements.
Requirement: The service provider must support Agency requirements to comply with M-21-31 (https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf).

Originally posted by @nolunwa-ucsc in #5078 (comment)

@github-actions github-actions bot added the orange [process] Done by the Azul team label Mar 19, 2024
@achave11-ucsc achave11-ucsc added enh compliance [subject] Information and software security - [priority] Medium labels Mar 19, 2024
@nolunwa-ucsc nolunwa-ucsc self-assigned this Aug 12, 2024
@nolunwa-ucsc
Copy link

A-Lign recommends the University of California, Santa Cruz review and update their record retention process to comply with the M-21-31 record retainage requirements.

@nolunwa-ucsc
Copy link

The team decided to increase the retention of all logs to 12 months.

@nolunwa-ucsc nolunwa-ucsc removed their assignment Aug 22, 2024
@nolunwa-ucsc
Copy link

Implementation due 2/1/2025

@achave11-ucsc
Copy link
Member

achave11-ucsc commented Dec 20, 2024

Assignee to file PR that sets the retention of every log (CloudTrail, CloudWatch, ElasticSearch, S3 access logs, load balancer logs, etc.) to 365 days.

@nolunwa-ucsc nolunwa-ucsc added + [priority] High and removed - [priority] Medium labels Jan 9, 2025
@nolunwa-ucsc
Copy link

this is due 2/1/2025 (POAM item)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
+ [priority] High compliance [subject] Information and software security demo [process] To be demonstrated at the end of the sprint orange [process] Done by the Azul team POAM 2024
Projects
None yet
Development

No branches or pull requests

4 participants