Knowing what happened.
WHAT TO ENABLE
Activity logging on cloud accounts Access logs for storage and applications Billing detail
WHY BEFORE YOU NEED IT
Logging cannot be enabled retrospectively.
An incident with logging disabled cannot be investigated.
WHAT LOGS SHOULD CAPTURE
Who did what, and when Resources created and changed Permission changes Access to sensitive data
WHERE TO KEEP THEM
Somewhere an attacker with account access cannot simply delete.
WHAT TO REVIEW
Periodically, and after anything unusual.
WHAT TO ALERT ON
Permission changes Root or owner account use Unexpected resource creation Unusual spend
WHAT NOT TO DO
Enable extensive logging nobody reads, at cost.
WHAT TO BALANCE
Enough to investigate, not so much that it costs more than it protects.
WHAT TO ESTABLISH
How long logs are kept.
WHAT TO CHECK
That logging is actually running.