166 terms · 75/46/45
Defense № 016 · class: monitoring / response

Logging & Monitoring

Logging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security incidents.

Term

description · examples · notes

Logging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security incidents.

Description

This technology is the foundation for all other detective controls. Without adequate logging, it is impossible to determine what happened during an incident, who was involved, and which systems were affected.

Effective logging requires defining what is recorded, how long it is retained, where it is stored, and who has access to the records. Logs must be protected from unauthorized modification to remain valid for forensic analysis.

What people often say

  • If logs are collected, threats are automatically detected.
  • Retaining logs for three months is always sufficient.

Covers / does not cover

Covers

  • Recording logins, resource access, and administrative actions
  • Tracking changes in system and application configuration
  • Foundation for forensic analysis after a security incident
  • Enabling event correlation in a SIEM system

Does not cover

  • Automatic threat detection (that requires correlation rules and analytics)
  • Real-time attack prevention
  • Monitoring encrypted network traffic without additional tools

Mentioned in the news

Composite

Threats

reduces 60

Techniques

neutralizes 41