graphgrc

Logging and Monitoring Standard

Requirements for security logging, monitoring, and alerting.

Scope

All production systems, applications, infrastructure, and SaaS applications.

Log Requirements

What to Log

Application logs:

Infrastructure logs:

SaaS audit logs:

What NOT to Log

Log Format

Log Storage

Centralization

Retention

Protection

Monitoring and Alerting

Critical Security Events (Page immediately)

Important Security Events (Alert in Slack)

Monitoring Coverage

Log Analysis

References

Control Mapping


Referenced By

This section is automatically generated by make generate-backlinks. Do not edit manually.