Proving log coverage instead of assuming it
The gap between collected and useful
Most estates collect a lot of log data and can still answer very few questions during an investigation. The reason is usually that nobody tested the collection path against the questions it is supposed to answer. Coverage is a property of a hypothesis, not of a source count.
Write the questions down
Start with the events the business actually needs to reconstruct. A defensible starting set:
- which account authenticated to which system from which address, and whether the authentication succeeded
- which privileged group membership changed and who approved it
- which process started on a server, with its parent, command line and signer
- which file share or database was accessed by a non-owner
- which outbound connection left the network after the first suspicious authentication
- which configuration change was applied to a security control, and by whom For each question, record where the answer exists, how long it is retained, and how it is queried. A question that has no answer is a finding, not a gap to be noted. NIST SP 800-92 covers the log management lifecycle that supports this, including the phases of generation, transmission, storage and analysis. NIST SP 800-137 describes continuous monitoring as the discipline that keeps the answers current rather than historical.
Test the path end to end
Generate the event deliberately, then look for it in the system the analyst will use during an incident, not in the source system. This step exposes the failures that matter: parsing rules that drop fields, time zone handling that shifts event order, retention that expires a window the investigation needs, and role-based access that prevents the responding analyst from reading the data.
Retention and volume are one decision
Storage cost sets the retention period, and the retention period sets what can be investigated. Where full retention is not affordable, tier the data: keep queryable full detail for a short window, and keep normalised metadata, such as authentication and privilege events, for a longer one. Decide which tier carries the legal and regulatory obligations before the incident, because that decision cannot be revisited under pressure.
References
- NIST SP 800-92, Guide to Computer Security Log Management — https://csrc.nist.gov/pubs/sp/800/92/final
- NIST SP 800-137, Information Security Continuous Monitoring — https://csrc.nist.gov/pubs/sp/800/137/final
- NIST SP 800-61 revision 2, incident handling guide — https://csrc.nist.gov/pubs/sp/800/61/r2/final
- OWASP logging cheat sheet — https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html
Top comments (0)