Skip to main content

ER-59 Pre-Kickoff - Log Management Policy, Configurations, and Alerts

Suzette Richards avatar
Written by Suzette Richards
Updated this week

Evidence from Security Logging Dashboard

Provide screenshots of the security log management dashboard or dashboards used to monitor all in-scope production systems for security related events.

For each tool that monitors events, the evidence should demonstrate:

  • What security events are being monitored

Security Event Alert Configurations or Example Alert

Provide screenshots of an example security event notification or alert message created by your security log management tools.

For each tool that monitors events, the evidence should demonstrate:

  • Which events will trigger a notification

  • Who receives a notification and how

Additional Guidance

Your log management may be covered by multiple tools, or a single log management tool (such as AWS CloudTrail, AWS GuardDuty, Azure Defender, or Google Security Command Center) may monitor several production systems by itself.

Example Evidence

AWS GuardDuty (Dashboard)

AWS GuardDuty (Alert Notification Configurations)

Google Security Command Center (Dashboard)

Google Security Command Center (Alert Notification Configurations)

Azure Defender (Dashboard)

Azure Defender (Alert Notification Configurations)

Associated Unified Control ID

Associated Framework Control

CTRL-833

LCL-48

Did this answer your question?