5. Log reviewing


At level 4 you were looking at the reports every now and then, but now someone decided you need to be on top of things and events pretty much on a daily basis. The reports/alerts created daily need to be quite granular and really tell you the state of your environment. At this stage you don't want to browse through hundreds of pages of false positives so some refining has to be done. reading that many pages not only takes way too much time, it also makes it impossible to focus on the really important things. If it takes too long and the real problems can't be distinguished easily, these reports will not be read after a while and thus not be acted upon. To reach this level takes a lot of groundwork. You will have to have the noise reduction in place, it has to be refined every now and then too. The reports, or dashboards, need to be designed so only the most important events are being displayed and therefore easy to attend to. There should be simple means to dig in to the data from the reports, in case there are ways of killing two birds with one stone. In the best of worlds these reports are more or less empty, so your daily review of the logs are kept to the minimum. This is the level you'll be if you are looking to meet compliance requirements for PCI for instance.

Comments

Popular posts from this blog

Overhead lines

R.I.P. Google Reader

Sweden 2 Australia