policy:data_privacy:log-in_monitoring
This is an old revision of the document!
Table of Contents
Log-in Monitoring
University Internal Standard
OIT has an internal standard for logging, monitoring and auditing that applies to all servers managed by CU Denver OIT. Click her to view the version that was effective as of July 1, 2017. Please contact OIT's Risk and Compliance team for the most up to date version.
According to the standard the following details are logged and saved on a centralized logging server for at least six months:
- Timestamp
- Event, status, and/or error codes
- Service/command/application name
- User or system account associated with an event
- Device used (e.g. source and destination IPs, terminal session ID, web browser, etc)
The events related to the following categories are logged:
- Operating System(OS) Events
- OS Audit Records
- Application Account Information
- Application Operations
- File Access (files containing ePHI or Highly Confidential information)
University of Colorado Denver HIPPA Policy
HIPAA Policy 9.3 Auditing http://www.ucdenver.edu/research/Research%20Administration%20Documents/9.3%20Auditing.pdf
policy/data_privacy/log-in_monitoring.1559764282.txt.gz · Last modified: 2019/06/05 19:51 by tonyromero