Forum
11

Security Policies - Logging Best practice

asked by gerald (Gerald) 24 days ago

We are writing our logging policy properly for the first time rather than the two paragraphs currently buried in the IT policy. What should actually be in it?

Every template I find is either three pages of nothing or forty pages of ISO boilerplate.

2 answers

Sign in to answer.
tony (Tony) 13 points 23 days ago

Six things, and it fits on two pages.

What is collected and from where, as an actual list rather than "all critical systems".
How it gets there and how it is protected in transit.
Who can read it, and how that access is granted and removed.
How long it is kept and why that number.
Who reviews it, how often, and what happens when they find something.
Who owns the policy and when it gets reviewed.

The test is whether somebody new could read it and know what to do. Forty pages fails that as badly as three paragraphs.

gerald (Gerald) 5 points 23 days ago

That is more or less exactly what I needed. The "why that number" on retention is the bit I would have skipped and then been asked about.

Guidelines Newest Search Back to Trunc