Tags: compliance, HIPAA
Class: ms_windows_event
Required List: cde_hostnames
164.308(a)(5)(ii)(C) - Log-in Monitoring: Successful Logins
Regulatory Text:
Procedures for monitoring log-in attempts and reporting discrepancies.
Successful Logins by Hostname: Displays successful logins by hostname that were established within the last 7 days.
Successful Logins by Source IPv4: Displays successful logins by source IPv4 that wereestablished within the last 7 days.
Successful Logins by Method: Displays successful logins by method that were established within the last 7 days.
Successful Logins by Username: Displays successful logins by username that were established within the last 7 days.
Successful Logins by Timestamp: Displays successful logins within the last 7 days.
.png)
164.308(a)(5)(ii)(C) - Log-in Monitoring: Failed Logins
Regulatory Text:
Procedures for monitoring log-in attempts and reporting discrepancies.
Failed Logins by Hostname: Displays failed logins by hostname that were established within the last 7 days.
Failed Logins by Source IPv4: Displays failed logins by source IPv4 that were established within the last 7 days.
Failed Logins by Method: Displays failed logins by method that were established within the last 7 days.
Failed Logins by Username: Displays failed logins by username that were established within the last 7 days.
Failed Logins by Timestamp: Displays failed logins within the last 7 days.
.png)
164.308(a)(3)(ii)(A) & 164.308(a)(3)(ii)(C) & 164.308(a)(4)(ii)(C) - Authorization and/or Supervision, Termination Procedures, Access Establishment and Modification
Regulatory Text:
Implement procedures for the authorization and/or supervision of workforce members who work with electronic protected health information or in locations where it might be accessed.
Implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends or as required by determinations made as specified in paragraph (a)(3)(ii)(B) of this section.
Implement policies and procedures that, based upon the covered entity’s or the business associate’s access authorization policies, establish, document, review, and modify a user’s right of access to a workstation, transaction, program, or process.
Users Modified: Displays user modifications within the last 7 days.
Users Created: Displays user creation within the last 7 days.
Users Deleted: Displays user deletion within the last 7 days.
User Modification Details: Display details regarding user modifications within the last 7 days.
User Modification by Timestamp: Illustrates user modifications by timestamp within the last 7 days.
.png)
164.308(a)(1)(ii)(D) - Information System Activity Review
Regulatory Text:
Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.
Updated System Level Objects by Hostname: Displays modified system level objects by hostname within the last 7 days.
Created System Level Objects by Hostname: Displays created system level objects by hostname within the last 7 days.
Deleted System Level Objects by Hostname: Displays deleted system level objects by hostname within the last 7 days.
System Level Objects by Timestamp: Illustrates all modifications to system level objects within the last 7 days.
