USDAForestService / fs-open-forest-platform

Open Forest: The code for an online permitting platform for the U.S. Forest Service.
https://openforest.fs.usda.gov
Other
38 stars 19 forks source link

File Integrity Monitoring #821

Closed smahmudFS closed 5 years ago

smahmudFS commented 5 years ago

Notes

Since Splunk integration is not going fast enough to meet the September 21 Deadline for POAM closure. We need to determine what can we do with the existing audit logs to perform minimal File Integrity Monitoring. Or better still would be to create a script that performs a checksum of the file or Directory and then the users get alerted to when a file has changed. Here is the link for the Splunk Simple FIM tool I intended to use just so we have this captured: https://gosplunk.com/simple-file-integrity-monitoring-management-dashboard/

@ Abdul - Please check to see if we can do at a minimum tasks 1 and 2. You may need to reach out to the development team for the information in task 1. Then we need to see if we have file level visibility via the exiting audit logs.

Acceptance Criteria

Tasks

Definition of Done

ASprinkle commented 5 years ago

@aaronburk @smahmudFS is this a story suited for the Program Board?

carlsonem commented 5 years ago

Will be moved over to the program board