Conducting Logging and Monitoring Activities
Logging and monitoring are key to ensuring that an incident gets detected as soon as it occurs. Many organizations implement logging and monitoring but do not do so consistently because they have not developed and implemented a log management and monitoring strategy. Such a strategy outlines what logs need to be collected, where they will be stored, how long they will be kept, and what happens afterward.
Log retention and storage is often a crucial component of compliance frameworks. The problem is that compliance frameworks tend to focus on historical incident data and, consequently, sometimes have an outdated view of what constitutes an incident.
With new types of attacks rapidly evolving, the needs of the security team do not always line up with what a strict compliance regime requires. Specifically, compliance requirements tend to lag behind the needs of incident response. A log management strategy needs to carefully distinguish...