Guidance
Your log management may be covered by multiple tools or a single log management tool may monitor several production systems by itself.
Common CSP-provided log management tools include:
AWS CloudTrail, CloudWatch, and GuardDuty
Azure Defender, Security Center, and Microsoft Sentinel
Google Security Command Center
The following systems are common event monitoring tools:
Intrusion detection systems
Endpoint management tools
Antivirus
Log management tools for production systems and infrastructure
Your log management tools monitor your in-scope production systems for events such as:
Actions taken by privileged or root users
Users accessing sensitive or customer data
Invalid login attempts
Malicious activity, such as DDoS attacks, brute force logins, etc.
Example Evidence
AWS GuardDuty (Dashboard)
AWS GuardDuty (Alert Notification Configurations)
Google Security Command Center (Dashboard)
Google Security Command Center (Alert Notification Configurations)
Azure Defender (Dashboard)
Azure Defender (Alert Notification Configurations)






