What is session recording?

Session recording captures a privileged session as it happens so that it can be replayed afterward. It answers a question that logs alone usually cannot: not just that someone connected, but what they actually did once they were in.

Privileged session → Recording → Review
Privileged session → Recording → Review

What a log gives you, and what it does not

Question A connection log A session recording
Who connected Yes Yes
To which system Yes Yes
When, and for how long Yes Yes
What commands were run Only if the target happened to log them Yes
What the screen showed No Yes, for graphical sessions
Whether a configuration was changed by hand No Yes

The gap matters most during an incident. An investigator with connection logs knows the window to suspect. An investigator with a recording knows what happened inside it.

What gets recorded

The kit records SSH, RDP, and VNC sessions, with replay, on the Level 3 kit. A terminal session captures the command stream. A graphical session captures the screen.

Recording is a control with real privacy weight. Three practices keep it defensible:

  1. Tell people. A logon banner that states sessions are recorded removes the surprise and strengthens the record.
  2. Scope it. Record privileged sessions on in-scope systems, not all activity everywhere.
  3. Protect the recordings. A recording of an administrator session contains whatever was on the screen. Treat it as sensitive data with its own access control and retention period.

Where frameworks ask for it

Framework Requirement
NIST SP 800-53 AU-14 Session Audit; AU-2 Event Logging; AU-9 Protection of Audit Information
NIST SP 800-171 3.3.1 create and retain audit records; 3.3.2 trace actions to individual users
CMMC Level 2 AU.L2-3.3.1, AU.L2-3.3.2
NIST SP 800-172 and CMMC Level 3 Enhanced monitoring of privileged activity
IEC 62443 Audit requirements for remote access to industrial systems

What the kit does

Item

  • Recorded SSH, RDP, and VNC sessions with replay, on the Level 3 kit
  • Jump, a managed access path for privileged sessions, isolated and recorded on the Level 3 kit
  • Command restriction that blocks dangerous commands as they are typed, so some actions never reach the recording because they never happen
  • Privileged-action and session records, Windows Event Log, and syslog in RFC 5424, CEF, or LEEF, routed per event type to a Security Information and Event Management (SIEM) platform such as Splunk, Microsoft Sentinel, Azure Monitor, Datadog, Amazon CloudWatch, or Google Cloud Logging
  • Assessment Binder, a living evidence package shared by the assessor, the Managed Service Provider, and the Customer
  • Universal host logon banner pushed to every system

See logging, SIEM, and event forwarding and CMMC Level 3.

Common questions

Is session recording the same as keystroke logging?

It overlaps but is narrower in scope and different in intent. Session recording captures a bounded privileged session on a named system. Keystroke logging usually implies continuous capture of a person's general activity.

How long should recordings be kept?

Long enough to be useful in an investigation and no longer than policy allows. Set the retention period deliberately, because recordings accumulate quickly and contain sensitive content.

Does recording slow the session?

The session is brokered, so there is a broker in the path either way. Recording is part of that path rather than an extra hop.

Who can watch a recording?

That should be a deliberate access decision with its own record. A recording that anyone can open is a new exposure, not a control.

Do we need recording at every CMMC level?

Recorded sessions with replay ship on the Level 3 kit. Audit records that trace actions to individual users are required earlier. See CMMC Level 2 and CMMC Level 3.

Related pages

Sources