NIST SP 800-92 Guide to Computer Security Log Management Audit
NIST SP 800-92 establishes federal requirements for computer security log management, covering log infrastructure, source configuration, retention, and ongoing analysis for federal systems and contractors. This checklist guides SIEM managers through each control area of the publication, from centralized log collection and NTP time synchronisation to retention policy verification and incident response log integration.
- Industry: Information Technology
- Frequency: Quarterly
- Estimated Time: 20-30 minutes
- Role: SIEM Manager
- Total Items: 27
- Compliance: NIST SP 800-92, NIST SP 800-53 (Audit and Accountability), NIST CSF 2.0, ISO/IEC 27001 A.12.4
NIST SP 800-92 (Guide to Computer Security Log Management, September 2006) is the foundational federal standard for log management programs. It establishes requirements for log generation, collection, storage, analysis, and protection across federal information systems. While the document was published in 2006, it remains the authoritative NIST reference for log management and is incorporated by reference in FedRAMP, FISMA, and CMMC compliance programs. NIST SP 800-92 defines three tiers of log data: security log data (audit trails, authentication events, security alerts), operational log data (system performance and availability), and audit log data for regulatory accountability.
The compliance obligation for federal agencies comes from FISMA (44 U.S.C. 3541), which requires agencies to implement NIST 800-92 as part of their information security programs, with OIG audits and OMB FISMA reporting as the accountability mechanism. For regulated private-sector organizations, NIST SP 800-92 is incorporated into PCI DSS (Requirement 10), HIPAA audit controls (45 CFR 164.312(b)), and CMMC (AU.2.041 through AU.3.046). The standard explicitly requires a centralized log management infrastructure, tamper-resistant log storage, defined retention periods, and documented analysis procedures - requirements that map directly to SIEM deployment in practice.
Log Management Infrastructure
Verify that a centralized log management infrastructure is deployed, sized, and protected to support continuous log collection across all systems.
- Is a centralized log management system (SIEM, syslog server, or log aggregator) deployed and operational for all in-scope systems?
- Has capacity planning been performed to confirm the log management infrastructure can sustain peak log volume without dropping events?
- Is the log management infrastructure documented in a current architecture diagram identifying all log sources, transport paths, and storage locations?
- Is administrative access to the log management system restricted to authorised personnel, with access controlled and separately logged?
- Are log management infrastructure components monitored for availability, with automated alerting on component failure or storage threshold breach?
- Attach screenshot confirming log management system operational status and current storage utilisation:
Log Generation and Source Configuration
Verify that all relevant log sources are generating appropriate events and forwarding them to the centralized log management system.
- Are all network devices (firewalls, routers, switches, VPN gateways) configured to forward logs to the centralized log server?
- Are operating system audit logs enabled on all servers and workstations, capturing logon/logoff, privilege use, object access, and process execution events?
- Are security application logs (antivirus, IDS/IPS, DLP, web application firewall) forwarded to and parsed by the log management system?
- Are application logs from business-critical and internet-facing systems configured to capture authentication, authorisation decisions, and application errors?
- Are all log sources synchronised to a common authoritative NTP time source, with clock drift monitored and corrected?
- Is the log source inventory reviewed periodically to confirm all expected sources are actively sending logs and decommissioned systems are removed?
Log Storage, Retention and Protection
Verify that logs are retained for defined periods, protected against tampering, and recoverable for investigation and compliance purposes.
- Does the organisation have a documented log retention policy specifying minimum retention periods by log type and applicable regulatory requirement?
- Are log files stored in a write-protected or append-only format that prevents modification or deletion by standard user or system accounts?
- Are log archives stored on infrastructure separate from the originating host, so a host compromise does not destroy that host's log evidence?
- Are log archives protected by cryptographic hash or digital signature at the point of archival, enabling detection of subsequent unauthorised alteration?
- Is access to raw log storage restricted and itself logged, with periodic review of who has accessed log archives?
Log Analysis and Review
Verify that logs are reviewed on a defined schedule and that automated correlation is in place to surface security-relevant events efficiently.
- Is there a documented schedule and assigned responsible role for routine log review, with review frequency proportionate to system criticality?
- Are automated correlation rules and alert thresholds configured in the SIEM or log analysis platform to surface high-priority security events?
- Has a documented baseline of expected log behaviour been established for critical systems, enabling anomaly detection when observed patterns deviate?
- Are log review findings documented for each review period, including anomalies investigated, their resolution, and any follow-up actions assigned?
- Are log analysis findings reported to system owners and management on a defined schedule?
Incident Response Integration
Verify that the log management program is integrated with incident response procedures and updated based on lessons learned.
- Does the incident response plan include documented procedures specifying which log sources to acquire, how to preserve them, and who is responsible during an incident?
- Are forensically critical log sources preserved in a documented chain-of-custody process upon incident declaration?
- Is there a post-incident review process that evaluates whether existing logging coverage was sufficient to detect and reconstruct the incident?
- Is there a documented process for deploying updated logging configurations (new sources, revised alert rules, extended retention) following identification of coverage gaps?
- Are incident-related logs placed under a legal hold extending their retention beyond the standard policy for the duration of any active investigation?
Related Technology Checklists
- NIST SP 800-94 IDS & IPS Monitoring & Maintenance Checklist
- ISO/IEC 27002:2022 Information Security Controls Audit Checklist
- ISO/IEC 27004 Information Security Measurement & Metrics Audit
- ISO/IEC 27005 Information Security Risk Management Process Audit
- CIS Benchmark Windows Server Hardening Compliance Checklist
- CIS Benchmark Linux Server Hardening Compliance Checklist
- OWASP Secure Development Lifecycle Application Security Checklist
- SOC 2 Type II Availability Criteria A1 Uptime & Resilience Audit
Related Cybersecurity Checklists
- NIST CSF 2.0 Govern Function - Policy & Oversight Audit Checklist - FREE Download
- NIST CSF 2.0 Identify Function - Asset Inventory Compliance Checklist - FREE Download
- NIST CSF 2.0 Protect Function - Access Controls Compliance Checklist - FREE Download
- NIST CSF 2.0 Detect Function - Continuous Monitoring Audit - FREE Download
- NIST CSF 2.0 Respond Function - Incident Response Plan Audit - FREE Download
- NIST SP 800-171 CUI Protection for Defense Contractors DFARS Audit - FREE Download
- ISO/IEC 27001:2022 Annex A Controls Implementation Checklist - FREE Download
- ISO/IEC 27001:2022 Clause 6.1.2 Information Security Risk Assessment - FREE Download
- ISO/IEC 27001:2022 Certification Readiness Gap Assessment Checklist - FREE Download
- SOC 2 Type II - CC6 Logical & Physical Access Controls Checklist - FREE Download
Why Use This NIST SP 800-92 Guide to Computer Security Log Management Audit?
This nist sp 800-92 guide to computer security log management audit helps information technology teams maintain compliance and operational excellence. Designed for siem manager professionals, this checklist covers 27 critical inspection points across 5 sections. Recommended frequency: quarterly.
Ensures compliance with NIST SP 800-92, NIST SP 800-53 (Audit and Accountability), NIST CSF 2.0, ISO/IEC 27001 A.12.4. Regulatory-aligned for audit readiness and inspection documentation.
Frequently Asked Questions
What is NIST SP 800-92 and what does it require?
NIST SP 800-92 (Guide to Computer Security Log Management, 2006) establishes the federal baseline for log management programs. It requires: (1) a log management policy defining what must be logged, retention periods, and responsibilities; (2) log source configuration - all critical systems generating security-relevant log data; (3) centralized log management infrastructure collecting logs from distributed sources into a protected, tamper-evident store; (4) secure log storage protecting logs from unauthorized modification or deletion; (5) log analysis - regular review of logs for security events and anomalies; and (6) incident response integration - logs accessible for forensic investigation within defined time windows. Federal agencies implement NIST 800-92 under FISMA. Private-sector organizations use it as the technical basis for PCI DSS Requirement 10, HIPAA audit controls, and CMMC AU domain compliance.
What log sources must be collected per NIST SP 800-92?
NIST SP 800-92 identifies these log source categories as requiring collection: operating system logs (authentication, privilege use, account changes, audit policy changes, system startup and shutdown); application logs (user access, sensitive function use, error events); security device logs (firewall accept and deny, IDS/IPS alerts, VPN authentication, DLP events); network device logs (router and switch authentication, configuration changes, DHCP leases); and antimalware logs (detection and remediation). For each source, NIST 800-92 recommends: enabling all security-relevant event types, timestamping with synchronized time sources (NTP), configuring forwarding to a centralized collection point, and retaining the original log format to preserve forensic value.
How does NIST 800-92 relate to SIEM requirements?
NIST SP 800-92 does not mandate a SIEM by name, but its requirements for centralized log collection, tamper-evident storage, correlation, and real-time alerting effectively describe what a SIEM (Security Information and Event Management) system provides. NIST 800-92 Section 3 (Establishing and Maintaining a Log Management Infrastructure) calls for a centralized log management server that aggregates logs, generates alerts for high-priority events, and provides search and analysis capabilities. FedRAMP and CMMC compliance interpretations treat SIEM deployment as the standard means of satisfying NIST 800-92 infrastructure requirements. NIST SP 800-137 (Information Security Continuous Monitoring) extends 800-92 log management requirements into the context of an ongoing ISCM program.
What is the required log retention period under NIST 800-92?
NIST SP 800-92 recommends a minimum of 1 year total retention with at least 3 months online (immediately accessible). Specific program requirements vary: FedRAMP requires 1 year total with 90 days online; PCI DSS Requirement 10.7 requires 12 months with 3 months immediately available; HIPAA audit programs typically apply a 6-year policy-retention period to system audit logs; CMMC AU.3.046 requires retention sufficient for after-the-fact forensic investigation. The NIST 800-92 guidance notes that retention periods must account for detection lag - if an intrusion goes undetected for 6 months, a 90-day retention policy means the initial compromise logs are already destroyed before the investigation begins.
What are common NIST SP 800-92 compliance failures?
Common NIST SP 800-92 compliance failures found during audits include: (1) log coverage gaps - systems generating security events but not forwarding to the centralized log management system, typically due to stale asset inventory or new systems not covered by logging policy; (2) time synchronization failures - log sources using different NTP servers or manually set clocks, making cross-source correlation unreliable; (3) log integrity controls absent - logs stored in writable locations accessible to the accounts that generated them; (4) retention period not met - log rotation deleting data before the policy retention period expires due to storage constraints; (5) analysis not performed - logs collected but never reviewed, satisfying collection requirements but failing the analysis and monitoring requirements; and (6) incident response log access untested - logs are retained but incident response teams have not verified they can query them during an active investigation.
What is a NIST SP 800-92 Guide to Computer Security Log Management Audit?
A NIST SP 800-92 Guide to Computer Security Log Management Audit is a standardized inspection form used by siem manager to ensure consistent information technology operations. It contains 34 inspection points organized into 5 sections. FREE PDF - NIST SP 800-92 computer security log management audit checklist. Covers SIEM deployment, log retention, analysis review, and incident response.
How often should I use this information technology checklist?
This checklist is designed to be completed quarterly. Regular use ensures compliance with NIST SP 800-92 and NIST SP 800-53 (Audit and Accountability) and helps identify issues before they become problems.
Can I download this NIST SP 800-92 Guide to Computer Security Log Management Audit as a PDF?
Yes, you can download this checklist as a FREE PDF for printing or offline use. The checklist includes 34 fields across 5 sections and typically takes 20-30 minutes to complete.
What compliance standards does this checklist cover?
This checklist helps ensure compliance with NIST SP 800-92, NIST SP 800-53 (Audit and Accountability), NIST CSF 2.0, ISO/IEC 27001 A.12.4. Following these standards protects your organization and ensures best practices.
How do I complete this information technology inspection checklist?
Begin by completing the header fields for Facility / Location, Inspection Date, Inspector Name, and Permit / Reference Number. Work through each of the 5 sections, marking items Yes or No as applicable. Finally, complete the footer fields and add your signature. The entire process takes approximately 20 to 30 minutes.
What are the key sections in this information technology checklist?
This information technology checklist is organized into 5 key sections: Log Management Infrastructure, Log Generation and Source Configuration, Log Storage, Retention and Protection, Log Analysis and Review, Incident Response Integration. Each section contains specific inspection points that siem manager must verify. The structured layout ensures nothing is missed during information technology inspections and makes the process efficient, typically taking 20-30 minutes to complete.
Who should use this NIST SP 800-92 Guide to Computer Security Log Management Audit?
This checklist is primarily designed for siem manager working in information technology operations. However, it is also valuable for quality assurance teams, safety officers, compliance managers, and supervisors who need to verify that information technology standards are being met. Organizations of all sizes can benefit from using this NIST SP 800-92 Guide to Computer Security Log Management Audit to maintain consistency and accountability.