All,

I just wanted to get some ideas as to how you are leveraging OSSEC to
meet PCI requirements.

I understand that with the FIM, basically, OSSEC needs to be installed
on the [monitored] servers/workstations for FIM to even work.

However, I have a couple outstanding questions:

1) Would OSSEC technically satisfy req 11.4 - "use intrusion-detection
systems..." - OSSEC is considered a HIDS isn't it? After reading
through it more, it seems like they are looking for a system where
there's a signature/rules engine that should be kept up-to-date of
course. We have a NIDS deployed and I figure OSSEC HIDS would just
supplement it, but not necessarily 'add' to the ability to satisfy req
11.4

2) I would assume 10.6 (daily review of logs) is covered by the fact
that OSSEC analyzes log files in real-time and will alert, email, etc
based on any triggers. Again, this sounds more like a 'supplemental'
type of thing where you can't just say "Oh, OSSEC fulfills 10.6
because it reads all the logs on a daily basis," right?

On that note: in terms of centralizing logs, are a lot of you remote
syslogging (in Linux... or using Snare i.e. for Windows) to a central
log server(s) and running OSSEC on the central log server with the
primary purpose of analyzing the syslogs as they flow in?
I guess, in agent mode, it doesn't matter either way. My main thing
here is that the logs need to be centralized, so even with an OSSEC
server-agent model, I would still need to ship the syslogs off to a
central location.
I'm just trying to get a feel as to whether or not one way would be
better than the other in terms of efficiency, etc.


Any ideas/thoughts would be appreciated.

TIA!!!

Reply via email to