Knowledgebase

Logging and Monitoring Access Print

  • 0

Knowing what happened.

WHY IT MATTERS

Without records, you cannot establish what a compromised account reached.

WHAT TO LOG

Sign-in attempts, successful and failed Privileged actions Access to sensitive data Changes to accounts and permissions Changes to security settings

WHY PERMISSION CHANGES SPECIFICALLY

Granting oneself access is a common step in misuse.

WHAT TO ESTABLISH

That logs are retained long enough to be useful.

HOW LONG

Long enough to investigate something discovered months later.

WHY

Compromises are frequently discovered long after they occur.

WHAT TO ESTABLISH

That logs are stored where those they record cannot alter them.

WHY

Logs an administrator can edit prove nothing about that administrator.

WHAT TO MONITOR ACTIVELY

Sign-ins from unexpected locations Repeated failed attempts Access outside normal hours Bulk data access New privileged accounts Changes to security configuration

WHY BULK ACCESS

It is the signature of data being taken.

WHAT TO ESTABLISH

Alerts for the things that matter.

WHAT TO AVOID

Alerting on everything.

WHY

Volume causes genuine alerts to be missed.

WHAT TO ESTABLISH

Who receives alerts and acts on them.

WHY

Alerts nobody reviews achieve nothing.

WHAT TO DO ABOUT AN ALERT

Establish whether it was legitimate.

HOW

Ask the person.

WHY

Most are explicable, and the exception is what matters.

WHAT TO RECORD

What was investigated and concluded.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot