▲
11
Security Policies - Logging Best practice
We are writing our logging policy properly for the first time rather than the two paragraphs currently buried in the IT policy. What should actually be in it?
Every template I find is either three pages of nothing or forty pages of ISO boilerplate.
Six things, and it fits on two pages.
What is collected and from where, as an actual list rather than "all critical systems".
How it gets there and how it is protected in transit.
Who can read it, and how that access is granted and removed.
How long it is kept and why that number.
Who reviews it, how often, and what happens when they find something.
Who owns the policy and when it gets reviewed.
The test is whether somebody new could read it and know what to do. Forty pages fails that as badly as three paragraphs.