What are some log collection-management considerations


Discussion Post

Log collection and management strategy is one of the most important decisions an organization can make as these logs provide pertinent event data that is used to identify potential compromises from external and internal threat actors, as well as organizational policy violations. For this discussion posting, I want you to respond to the following questions:

• What are some log collection/management considerations that an organization might need to bear in mind?

• Do log files unto themselves provide an organization with complete visibility into what's occurring on the organization's network or to support internal investigations? If not, what other data sources might you think would provide enrichment to the existing data set?

• Research centralized security incident and event management systems. Provide a summary of the features they contain and provide your assessment on how these features can be used by an organization (SOC analyst, threat hunting team, or incident responder) to help support investigations? Are there any particular features that might be useful to help with regulatory compliance reporting?

Request for Solution File

Ask an Expert for Answer!!
Management Information Sys: What are some log collection-management considerations
Reference No:- TGS03261175

Expected delivery within 24 Hours