Records of what happened.
WHY KEEP THEM
To investigate incidents To demonstrate control To meet obligations, where they apply
WHAT TO RECORD
Who accessed what, and when Changes to configuration and access Deployments Administrative actions Access to sensitive data
WHERE TO KEEP THEM
Somewhere the people being recorded cannot alter.
WHY
Otherwise the record is worthless after a compromise.
WHAT TO RETAIN
Long enough to investigate, and no longer than necessary.
WHAT TO PROTECT
The records themselves, which may contain sensitive detail.
WHAT TO REVIEW
Periodically, and after any incident.
WHAT OBLIGATIONS MAY APPLY
Depending on your sector, your customers and the data you hold.
Take advice on your position.
Visit zillionkinghost.com for further information.
WHAT TO BE ABLE TO ANSWER
Who had access, when What changed, when, and by whom When something was detected
WHAT TO AUTOMATE
The recording, so it does not depend on anyone remembering.