Link to home
Start Free TrialLog in
Avatar of Steph_M
Steph_MFlag for United States of America

asked on

File Intregrity Monitoring for Linux CentOS - what are you monitoring for regulatory obligations?

PCI "10.5.5 Verify the use of file integrity monitoring or change detection software for logs by examining system settings and monitored files and results from monitoring activities"  and  "11.5 verify the use of file-integrity monitoring products within the cardholder data environment by observing system settings and monitored files, as well as reviewing results from monitoring activities. Examples of files that should be monitored: System executables, Application executables, configuration and parameter files, centrally stored, historical or archived, log and audit files."

These requirements are causing us some grief because everyone has a different opinion as to what should be monitored and how.

The files are on Linux with CentOS.

Can you please tell me how you are satisfying this requirement? Are you using any special software, custom scripts, etc?  Which directories and/or files are you monitoring?

Any recommendations or suggestions you can offer would be greatly appreciated.

Thanks again Experts!

Steph M
Avatar of Rich Rumble
Rich Rumble
Flag of United States of America image

OSSEC is what we use, for win32 and *nix. It has most of the default file locations and logs covered, but you would have to tailor the config to suite specific or non standard install locations. Tripwire, and others are available, even splunk can do FIM and naturally log monitoring, but they cost more than OSSEC, which is free, however there are paid versions available from TrendMicro of the OSSEC product.
-rich
Since we are in financial domain so we are more concern about that and we are using etrust in our environment. But it is paid.
ASKER CERTIFIED SOLUTION
Avatar of dead_philosopher
dead_philosopher

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Steph_M

ASKER

OSSEC was chosen.

Thank you.