Security Log Centralization
ClosePart of SIEM.
- What it is
- Security-relevant logs from applications, platforms and security tools are collected centrally and retained.
- Why it matters
- Logs that stay on the machine are lost when it is replaced, and can be edited by whoever compromised it.
- You have it when
- Security-relevant logs from applications, platforms and security tools are shipped to a central store outside the systems that produce them, and kept for a defined period.
What is wrong
No remediation deadline — expected a remediation deadline, actual none
The thing in place is Azure Monitor log pipeline.
Required as mandatory: Required by profile rule(s): PERSONAL_DATA_PROTECTION, PERSONAL_DATA_INTERNET_EXPOSURE
Every scope this job would settle
| Environment | Technology | Phase | Control point | Weight |
|---|
| Production | any | Monitor / Respond | SIEM | 1 |
Something you already own
Nothing you already run claims to do this job.
See the whole capabilityChange an answer