DRAFT: Monitoring and Audit Standard

Tags Standard

Purpose

This standard establishes the requirements for monitoring, logging, auditability, alerting, and operational visibility for University-managed technology solutions.

The standard defines the controls necessary to support operational management, governance oversight, security investigations, compliance activities, incident response, and accountability.

Scope

This standard applies to:

  • Applications
  • Databases
  • Data platforms
  • Infrastructure services
  • Cloud services
  • Software-as-a-Service solutions
  • Integration services
  • Platform services
  • Identity services
  • Shared services
  • University-managed technology environments

Monitoring Principles

Operational Visibility

Technology solutions shall provide sufficient visibility to support operations, troubleshooting, service management, and support activities.

Security Visibility

Security-relevant activities shall be observable and available to support security investigations, incident response, and governance activities.

Auditability

Technology solutions shall generate sufficient audit information to support accountability, compliance reviews, investigations, and governance oversight.

Centralized Monitoring

Monitoring and audit information should be collected through approved enterprise monitoring capabilities whenever practical.

Monitoring Requirements

Technology solutions shall generate operational and security telemetry appropriate to the workload classification, data classification, and applicable obligations.

Monitoring implementations should support:

  • Operational health monitoring
  • Service availability monitoring
  • Capacity monitoring
  • Performance monitoring
  • Configuration change visibility
  • Security event visibility

Logging Requirements

Technology solutions shall generate logs appropriate to the capabilities they provide and the risks they present.

Operational Logs

Operational logs should provide visibility into system operations, service activities, platform activities, and resource management.

Security Logs

Security logs should provide visibility into security-relevant activities, administrative activities, authentication events, authorization events, and security investigations.

Audit Logs

Audit logs should support accountability, compliance activities, investigations, governance reviews, and operational reviews.

Application Logs

Applications should generate logs sufficient to support operational support, troubleshooting, diagnostics, and service management.

Identity and Access Monitoring

Authentication, authorization, privileged access, role assignments, and access governance activities shall be monitored and auditable.

Monitoring should support:

  • Authentication review
  • Authorization review
  • Privileged access review
  • Access governance activities
  • Security investigations

Alerting Requirements

Technology solutions should generate alerts for operational and security conditions requiring response.

Operational Alerts

  • Service degradation
  • Service outage
  • Capacity thresholds
  • Resource failures

Security Alerts

  • Administrative activity
  • Unexpected access activity
  • Security events
  • Investigation triggers

Retention Requirements

Monitoring and audit records shall be retained according to:

  • University policies
  • Regulatory requirements
  • Contractual obligations
  • Records management requirements
  • Governance requirements

Incident Investigation Support

Monitoring and logging capabilities shall support investigation of operational events, security incidents, compliance concerns, and governance activities.

Monitoring information should support:

  • Security investigations
  • Incident response
  • Operational reviews
  • Compliance reviews
  • Audit activities

Separation of Duties

Monitoring administration, monitoring services, and investigation activities should support separation of duties whenever practical.

Monitoring capabilities should not rely solely on workload owners for operational visibility or investigative access.

Shared Services

Enterprise monitoring and logging services may operate as approved shared services supporting multiple workloads.

Shared monitoring services shall:

  • Support auditability
  • Support investigations
  • Support operational visibility
  • Protect monitoring information appropriately
  • Support accountability requirements

Workload Classification Alignment

Innovation Workloads

Innovation workloads shall implement monitoring capabilities appropriate to experimentation, supportability, and operational ownership requirements.

Enterprise Workloads

Enterprise workloads shall implement monitoring, logging, auditability, and operational visibility capabilities supporting the enterprise control baseline.

Regulated Workloads

Regulated workloads shall implement enhanced monitoring, auditability, security visibility, retention, investigation support, and governance requirements.

Governance and Review

Monitoring implementations shall support governance reviews, operational oversight, compliance reviews, and architecture review activities.

Monitoring implementations that materially deviate from approved standards, patterns, or governance requirements require architecture review.

Exceptions

Exceptions to this standard require documented approval through the approved architecture exception process.