Monitoring and Logging
Andrew Chambers, Graham K. Rand · 2012
This chapter presents an overview of the monitoring and logging of IT systems, asserting how the organization is advised to have a defined and documented approach to monitoring and logging which takes into account the likely associated risks, the IT resource implications, the need to ensure compliance with policies and procedures, and matters of the legality of such monitoring. Logging activities in most application and operating software can often be at a very low level of functionality and so it is necessary to assess and determine the optimum level required in each case. If possible, and to avoid undue resource or performance impacts, logging should be tailored to a range of specified exceptions. If this defined extraction of events of interest were linked to the generation of appropriately periodic reports, management monitoring and oversight could be applied. IT logs are often referred to as audit logs and it is suggested that these are retained for at least six months before being removed.