Knowing what happened.
WHY IT MATTERS
Without records, you cannot establish what a compromised account reached.
WHAT TO LOG
Sign-in attempts, successful and failed Privileged actions Access to sensitive data Changes to accounts and permissions Changes to security settings
WHY PERMISSION CHANGES SPECIFICALLY
Granting oneself access is a common step in misuse.
WHAT TO ESTABLISH
That logs are retained long enough to be useful.
HOW LONG
Long enough to investigate something discovered months later.
WHY
Compromises are frequently discovered long after they occur.
WHAT TO ESTABLISH
That logs are stored where those they record cannot alter them.
WHY
Logs an administrator can edit prove nothing about that administrator.
WHAT TO MONITOR ACTIVELY
Sign-ins from unexpected locations Repeated failed attempts Access outside normal hours Bulk data access New privileged accounts Changes to security configuration
WHY BULK ACCESS
It is the signature of data being taken.
WHAT TO ESTABLISH
Alerts for the things that matter.
WHAT TO AVOID
Alerting on everything.
WHY
Volume causes genuine alerts to be missed.
WHAT TO ESTABLISH
Who receives alerts and acts on them.
WHY
Alerts nobody reviews achieve nothing.
WHAT TO DO ABOUT AN ALERT
Establish whether it was legitimate.
HOW
Ask the person.
WHY
Most are explicable, and the exception is what matters.
WHAT TO RECORD
What was investigated and concluded.