TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

LOG-8 – User Behaviors Analytics (UBA)

Estimated reading: 3 minutes 2709 views

What is LOG-8 user behaviour analytics (UBA) control?

One of the many controls, LOG-8 User Behaviour Analytics (UBA), is about having a process in place to gather insights into the network events that users generate and analyze the events to detect the use of compromised credentials, lateral movement, and other malicious behaviour.

LOG-8 user behavior analytics (UBA) control is a tool that allows organizations to monitor and analyze the behavior of users within their network or system. UBA control helps identify any abnormal or suspicious activities that may indicate a potential security threat.

LOG-8 control leverages advanced algorithms and machine learning techniques to detect patterns and anomalies in user behavior, such as unusual login attempts, data access patterns, or changes in user privileges. By analyzing user behavior, organizations can proactively identify and mitigate insider threats, unauthorized access attempts, or other security breaches. LOG-8 control provides valuable insights into user activities, helping organizations improve their overall security posture and protect sensitive data from unauthorized access or misuse.

Typically, networks gather information related to users moving between IPs, assets, cloud services, and mobile devices. LOG-8, on the other hand, focuses on user activity as opposed to static threat indicators. The goal is to use UBA information to detect attacks that haven’t been mapped to threat intelligence and alert on malicious behaviour earlier in an attack.

There are no mandatory methods to use in gathering and analyzing the events.

Available tools in the marketplace

The following listing is “crowdsourced” from our customer base or from external research. TrustCloud does not personally recommend any of the tools below because we haven’t used them.

Tools
Fullstory
Amplitude

Available templates

The following listing is “crowdsourced” from our customer base or from external research. TrustCloud does not personally recommend any of the tools below because we haven’t used them.

  1. N/A: no template recommendation

Control implementation

To implement this control,

Implement a UBA tool to collect and analyze the events. The implementation of the tool should take into account:

  1. Defining use cases such as identifying malicious insiders, compromised users, known security threats, and zero-day vulnerabilities
  2. Defining the data sources, such as events and logs; HR data; corporate emails; social media activity; network flows and packets
  3. Defining the behaviors about which data will be collected, such as work habits, user activities, context, biometrics,
  4. Establishing a baseline
  5. Training your employees on the tool
  6. Constant monitoring and rebuilding of the baseline periodically.

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below-suggested action:

  1. Screenshots of the UBA tool dashboard
  2. Screenshot of the UBA alert notifications

Evidence example

For the suggested action, an example is provided below:

  1. Screenshots of the UBA tool dashboard.
    The following screenshot shows the UBA tool dashboard.
    Here is the source.
    LOG 8 User Behaviors AnalyticsUBA 01
  2. Screenshot of the UBA alert notifications.
    The following screenshot shows the UBA alert notifications. Here is the source.
    LOG 8 User Behaviors AnalyticsUBA 02

Join the conversation

You might also be interested in

Custom Frameworks

TrustCloud supports several standards and frameworks out of the box, including SOC 2, CMMC,...

Hybrid Data Fabric

Rather than chasing fragmented spreadsheets or outdated lists, hybrid data fabric gives you a...

Systems

A system is a piece of software, either built by the organization or purchased...

Groups in Controls

TrustCloud provides you with a comprehensive set of controls to get certified against several...

Mapping a Control

TrustCloud’s common controls framework maps a comprehensive set of certified standards controls and your...

Sharing Controls with customers

The TrustShare application in TrustCloud makes it easy for startups, SMBs, and enterprises to...

Excluding a control, test or attestation

The exclusion allows you to remove certain resources, controls or tests from your program...

Control Attributes

Every control has many attributes that help us understand it better for mapping and...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue