Table of Contents
Log-in Monitoring
University Internal Standard
OIT has an internal standard for logging, monitoring and auditing that applies to all servers managed by CU Denver OIT. Click her to view the version that was effective as of July 1, 2017. Please contact OIT's Risk and Compliance team for the most up to date version.
According to the standard the following details are logged and saved on a centralized logging server for at least six months:
- Timestamp
- Event, status, and/or error codes
- Service/command/application name
- User or system account associated with an event
- Device used (e.g. source and destination IPs, terminal session ID, web browser, etc)
The events related to the following categories are logged:
- Operating System(OS) Events
- OS Audit Records
- Application Account Information
- Application Operations
- File Access (files containing ePHI or Highly Confidential information)
University of Colorado Denver HIPPA Policy
As applicable, the most secure SEHD data are subject to the UCD Auditing HIPAA Policy 9.3. The auditing policy requires units that hold medium to high risk ePHI must create a Audit Control and review Plan. Within that plan it states:
The system hardware, software, and applications must have the capability of creating log files. These logs must include, but are not limited to:
- User ID;
- Login date/time; and,
- Activity time.
Units must monitor login success and failure to systems that host ePHI. To ensure that unauthorized login attempts are discovered, discrepancies or unusual login patterns must be reported to the department administrator and HIPAA Security Officer.