Windows Security Logging and Monitoring Policy
Andrei Miroshnikov · 2018
The purpose of the security logging and monitoring (SL&M) policy is to ensure the confidentiality, integrity, and availability of information by specifying the minimum requirements for SL&M of company systems. This chapter outlines the requirements for what needs to be logged and how logs need to be managed. Implementing the recommendations can mitigate the risk of an attacker's activities going unnoticed and enhance a company's ability to conclude whether an attack led to a breach. Security analysts regularly review and analyze the collected logs according to a documented and approved schedule to ensure relevancy and adequacy of collected information. The chapter presents the requirements for monitoring of logs, intrusion detection systems, and internal communications, as well as mandates for a performance review of monitoring systems. Network-based intrusion detection systems (NIDS) are designed to provide monitoring and support of network intrusion detection across a variety of platforms and technologies.