All, I just wanted to get some ideas as to how you are leveraging OSSEC to meet PCI requirements.
I understand that with the FIM, basically, OSSEC needs to be installed on the [monitored] servers/workstations for FIM to even work. However, I have a couple outstanding questions: 1) Would OSSEC technically satisfy req 11.4 - "use intrusion-detection systems..." - OSSEC is considered a HIDS isn't it? After reading through it more, it seems like they are looking for a system where there's a signature/rules engine that should be kept up-to-date of course. We have a NIDS deployed and I figure OSSEC HIDS would just supplement it, but not necessarily 'add' to the ability to satisfy req 11.4 2) I would assume 10.6 (daily review of logs) is covered by the fact that OSSEC analyzes log files in real-time and will alert, email, etc based on any triggers. Again, this sounds more like a 'supplemental' type of thing where you can't just say "Oh, OSSEC fulfills 10.6 because it reads all the logs on a daily basis," right? On that note: in terms of centralizing logs, are a lot of you remote syslogging (in Linux... or using Snare i.e. for Windows) to a central log server(s) and running OSSEC on the central log server with the primary purpose of analyzing the syslogs as they flow in? I guess, in agent mode, it doesn't matter either way. My main thing here is that the logs need to be centralized, so even with an OSSEC server-agent model, I would still need to ship the syslogs off to a central location. I'm just trying to get a feel as to whether or not one way would be better than the other in terms of efficiency, etc. Any ideas/thoughts would be appreciated. TIA!!!
