I have a bit of a mystery on my hands. We had a new team member start recently. His ESM login was created by the CISO on February 1st; the next day he was on the email distribution list of a report that he hadn't been authorized for. The report has each email recipient defined seperately, I'm not using groups on this one.
The System Log doesn't have a record showing that the report was modified. The CISO claims ignorance.
Does anyone have any idea how this could have happened, or where I can find more of an audit trail?
Any help is appreciated.
Ussely a Machine dosn't make mistakes.... 😂😂😂
I would Check the followings:
1- the groups that the CISO user is grouped (Reporting etc.)
2- if a alarm is configured to trigger a Report. and the recipients of the alarm is the CISO.
3 - who else got the email that the CISO got. try to see the Matching points between them.
Thanks for the suggestions. It isn't the CISO who is receiving the report, it's someone new who works for him. We are small, easily controlled environment, and in this case there is ONLY one possibility - someone manually added this reciepient to the report. I guess what I'm really asking is where there is an audit trail that would show this operation.