adoptium / adoptium/infrastructure

EPIC: Define & Implement Access Auditing Policy & Tools

Open
#3,047 1 comment 0 reactions 1 assignee Claimed by @steelhead31 View on GitHub
secure-dev security
Dominant language
Python
Stars
96
Forks
106
Avg merge
1d 23h
Merged PRs (30d)
13

Description

As part of Secure Dev, we need to define an access auditing policy, and implement tools/processes to provide this service.

This issue is set up to track work relating to this piece..

Tasks
\------------------

1) Investigate monitoring strategies & applicable tools : #2968 - Done

2) Detail Next Steps For Preferred Tool : #3076 - Done

3) Deploy Wazuh To All Build Hosts : Done: 08/11/2023 : https://github.com/adoptium/infrastructure/issues/3235

4) Create Wazuh Code & Configuration Snippets Area in Infrastructure Repository.: https://github.com/adoptium/infrastructure/pull/3262- Complete

5) Create mechanism for tracing ssh logins: [Issue 3212](https://github.com/adoptium/infrastructure/issues/3212) : - Complete

6) Update Wazuh to current version, and define upgrade process and policy for both Wazuh server and agents. - 10/07/2024 - Completed: https://github.com/adoptium/infrastructure/issues/3654

7) Create DNS Name For Wazuh Server - EF issue raised : https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/5076 ( 04/10/2024 ) - Completed - 07/10/2024

8) Add certificates & configure https - https://github.com/adoptium/infrastructure/issues/3768

9) Define critical alerts & create filters.
10) [Create & Configure Slack Integration For Critical Alerts](https://github.com/adoptium/infrastructure/issues/3813)
11) Deploy Wazuh To All Test Hosts
12) Investigate how to build Wazuh agent from source on RHEL8 / s390x
13) Investigate how to build Wazuh agent from source on RISCV build machines
14) Investigate Auditing SSH/SSHD versions using Wazuh

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.