NIST SP 800-92 Guide to Computer Security Log Management Audit

NIST SP 800-92 establishes federal requirements for computer security log management, covering log infrastructure, source configuration, retention, and ongoing analysis for federal systems and contractors. This checklist guides SIEM managers through each control area of the publication, from centralized log collection and NTP time synchronisation to retention policy verification and incident response log integration.

  • Industry: Information Technology
  • Frequency: Quarterly
  • Estimated Time: 20-30 minutes
  • Role: SIEM Manager
  • Total Items: 27
  • Compliance: NIST SP 800-92, NIST SP 800-53 (Audit and Accountability), NIST CSF 2.0, ISO/IEC 27001 A.12.4

NIST SP 800-92 (Guide to Computer Security Log Management, September 2006) is the foundational federal standard for log management programs. It establishes requirements for log generation, collection, storage, analysis, and protection across federal information systems. While the document was published in 2006, it remains the authoritative NIST reference for log management and is incorporated by reference in FedRAMP, FISMA, and CMMC compliance programs. NIST SP 800-92 defines three tiers of log data: security log data (audit trails, authentication events, security alerts), operational log data (system performance and availability), and audit log data for regulatory accountability.

The compliance obligation for federal agencies comes from FISMA (44 U.S.C. 3541), which requires agencies to implement NIST 800-92 as part of their information security programs, with OIG audits and OMB FISMA reporting as the accountability mechanism. For regulated private-sector organizations, NIST SP 800-92 is incorporated into PCI DSS (Requirement 10), HIPAA audit controls (45 CFR 164.312(b)), and CMMC (AU.2.041 through AU.3.046). The standard explicitly requires a centralized log management infrastructure, tamper-resistant log storage, defined retention periods, and documented analysis procedures - requirements that map directly to SIEM deployment in practice.

Log Management Infrastructure

Verify that a centralized log management infrastructure is deployed, sized, and protected to support continuous log collection across all systems.

  • Is a centralized log management system (SIEM, syslog server, or log aggregator) deployed and operational for all in-scope systems?
  • Has capacity planning been performed to confirm the log management infrastructure can sustain peak log volume without dropping events?
  • Is the log management infrastructure documented in a current architecture diagram identifying all log sources, transport paths, and storage locations?
  • Is administrative access to the log management system restricted to authorised personnel, with access controlled and separately logged?
  • Are log management infrastructure components monitored for availability, with automated alerting on component failure or storage threshold breach?
  • Attach screenshot confirming log management system operational status and current storage utilisation:

Log Generation and Source Configuration

Verify that all relevant log sources are generating appropriate events and forwarding them to the centralized log management system.

  • Are all network devices (firewalls, routers, switches, VPN gateways) configured to forward logs to the centralized log server?
  • Are operating system audit logs enabled on all servers and workstations, capturing logon/logoff, privilege use, object access, and process execution events?
  • Are security application logs (antivirus, IDS/IPS, DLP, web application firewall) forwarded to and parsed by the log management system?
  • Are application logs from business-critical and internet-facing systems configured to capture authentication, authorisation decisions, and application errors?
  • Are all log sources synchronised to a common authoritative NTP time source, with clock drift monitored and corrected?
  • Is the log source inventory reviewed periodically to confirm all expected sources are actively sending logs and decommissioned systems are removed?

Log Storage, Retention and Protection

Verify that logs are retained for defined periods, protected against tampering, and recoverable for investigation and compliance purposes.

  • Does the organisation have a documented log retention policy specifying minimum retention periods by log type and applicable regulatory requirement?
  • Are log files stored in a write-protected or append-only format that prevents modification or deletion by standard user or system accounts?
  • Are log archives stored on infrastructure separate from the originating host, so a host compromise does not destroy that host's log evidence?
  • Are log archives protected by cryptographic hash or digital signature at the point of archival, enabling detection of subsequent unauthorised alteration?
  • Is access to raw log storage restricted and itself logged, with periodic review of who has accessed log archives?

Log Analysis and Review

Verify that logs are reviewed on a defined schedule and that automated correlation is in place to surface security-relevant events efficiently.

  • Is there a documented schedule and assigned responsible role for routine log review, with review frequency proportionate to system criticality?
  • Are automated correlation rules and alert thresholds configured in the SIEM or log analysis platform to surface high-priority security events?
  • Has a documented baseline of expected log behaviour been established for critical systems, enabling anomaly detection when observed patterns deviate?
  • Are log review findings documented for each review period, including anomalies investigated, their resolution, and any follow-up actions assigned?
  • Are log analysis findings reported to system owners and management on a defined schedule?

Incident Response Integration

Verify that the log management program is integrated with incident response procedures and updated based on lessons learned.

  • Does the incident response plan include documented procedures specifying which log sources to acquire, how to preserve them, and who is responsible during an incident?
  • Are forensically critical log sources preserved in a documented chain-of-custody process upon incident declaration?
  • Is there a post-incident review process that evaluates whether existing logging coverage was sufficient to detect and reconstruct the incident?
  • Is there a documented process for deploying updated logging configurations (new sources, revised alert rules, extended retention) following identification of coverage gaps?
  • Are incident-related logs placed under a legal hold extending their retention beyond the standard policy for the duration of any active investigation?

Related Technology Checklists

Related Cybersecurity Checklists

Why Use This NIST SP 800-92 Guide to Computer Security Log Management Audit?

This nist sp 800-92 guide to computer security log management audit helps information technology teams maintain compliance and operational excellence. Designed for siem manager professionals, this checklist covers 27 critical inspection points across 5 sections. Recommended frequency: quarterly.

Ensures compliance with NIST SP 800-92, NIST SP 800-53 (Audit and Accountability), NIST CSF 2.0, ISO/IEC 27001 A.12.4. Regulatory-aligned for audit readiness and inspection documentation.

Frequently Asked Questions

What does the NIST SP 800-92 Guide to Computer Security Log Management Audit cover?

This checklist covers 27 inspection items across 5 sections: Log Management Infrastructure, Log Generation and Source Configuration, Log Storage, Retention and Protection, Log Analysis and Review, Incident Response Integration. It is designed for information technology operations and compliance.

How often should this checklist be completed?

This checklist should be completed quarterly. Each completion takes approximately 20-30 minutes.

Who should use this NIST SP 800-92 Guide to Computer Security Log Management Audit?

This checklist is designed for SIEM Manager professionals in the information technology industry. It can be used for self-assessments, team audits, and regulatory compliance documentation.

Can I download this checklist as a PDF?

Yes, this checklist is available as a free PDF download. You can also use it digitally in the POPProbe mobile app for real-time data capture, photo documentation, and automatic reporting.

What is NIST SP 800-92 and who must implement it?

NIST SP 800-92 (Guide to Computer Security Log Management) provides guidance on establishing log management policies, log source configuration, centralized collection, secure storage, analysis, and retention for federal information systems. Federal agencies implement it under FISMA (44 U.S.C. 3541) and OMB Circular A-130. FedRAMP-authorized cloud service providers must demonstrate NIST 800-92-aligned log management to maintain authorization. Private-sector organizations in regulated industries use NIST 800-92 as the technical baseline for log management controls required by PCI DSS Requirement 10, HIPAA audit control standard 45 CFR 164.312(b), CMMC AU domain, and SOC 2 CC7.2 (monitoring of security events).

What log sources must be collected per NIST SP 800-92?

NIST SP 800-92 identifies these log source categories as requiring collection and retention: (1) Operating system logs - authentication events, privilege use, system startup and shutdown, audit policy changes; (2) Application logs - user activity, access to sensitive functions, error and exception events; (3) Security device logs - firewall allow and deny records, IDS/IPS alerts, VPN authentication; (4) Network device logs - router and switch authentication and configuration changes; and (5) Antimalware logs - detection, quarantine, and remediation events. For each source, NIST 800-92 recommends configuring real-time forwarding to a centralized log management system, using synchronized time sources (NTP) for all log timestamps, and retaining the original log format to preserve forensic value.

How long must logs be retained under NIST SP 800-92?

NIST SP 800-92 recommends a minimum of 1 year total retention with at least 90 days of immediately accessible (online) log data for incident response and forensic analysis. In practice, regulated programs apply these requirements: FedRAMP requires 1-year retention (90 days online, remainder archiveable); CMMC Level 2 AU.3.046 requires retention sufficient for after-the-fact investigation; PCI DSS Requirement 10.7 requires 12 months of audit log history with at least 3 months immediately available; HIPAA audit programs typically extend the 6-year policy-retention period to system logs. Organizations subject to legal hold must retain relevant logs for the duration of any pending investigation regardless of the standard rotation schedule.

Browse More Checklists

POPProbe