Log Aggregation, Risk and Control Monitoring, and Reporting
This is the last chapter of Domain 3: Risk Response and Reporting and is divided into two parts. In the first part, we will look at the different sources for collecting logs, tools, and best practices to aggregate them, and how to analyze those logs. In the second part, we will look at risk and control monitoring, different control assessments, risk and control reporting methods, different key indicators for an executive summary, and the appropriate audience for each.
The aim of this chapter is to learn about the different methods of log sources, aggregation, and analysis. We will also learn about risk and control monitoring, reporting, and how to present reports effectively.
In this chapter, we will cover the following topics:
- Log aggregation and analysis
- Security information and event management
- Risk and control monitoring
- Risk and control reporting
- Key indicators
With that, let us dive...