Table of Contents

Inspector

Project description

Ensure the existing Audit framework for the critical components in OPNFV are extensive enough and compliant to industry standards and foreseeable business use cases.

The benefit is that:

For any NFV provider, it is necessary to provide audit data relevant to the specific industry requirements in a standard format

Scope

It is currently not possible to easily assess Cloud deployments compliance against an auditing standard There are still several components that do not have sufficient infrastructure to enable auditing such as OpenStack and ODL.

There doesn't exist an implementation to assess the integrity of audit logs in the tools we are basing OPNFV in.

Proposal

Specify testing and integration

Ensure that CADF compliant, signed log files are sampled in verification.

Debugging and Tracing

In the case of OpenStack, verify that Ceilometer reports appropriate audit data

Unit/Integration Test plans

In the case of OpenStack, ensure that logs are properly set in Ceilometer

Considerations

Dependencies

Tightly linked to OpenStack release cycle

Open source projects currently aimed at:

Committers and Contributors:

Names and affiliations of the committers:

Names and affiliations of any other contributors:

Planned deliverables

Proposed Release Schedule:

Aligned with OpenStack Liberty release

Getting Started

CADF / Keystone Example Set Up

OpenDayLight Install

References

DSP 0262, Cloud Audit Data Federation (CADF) – Data Format and Interface Specification by Distributed Management Task Force DSP 2038, Cloud Audit Data Federation – OpenStack Profile (CADF-OpenStack)