Troubleshooting auditing
Auditing is an essential component of a robust system architecture, but it is only as effective as your strategy surrounding it; simply having audit logs does not guarantee “robust auditing.” It is therefore important to periodically review your auditing practice itself, much as you periodically review the audit logs, to ensure you are making the most of the data you have collected. Some factors you should consider during these strategic reevaluations include the following:
- Frequency of audit review: Is the frequency with which you review your audit logs appropriate to the activity load of your system? Too infrequent and it becomes harder to find the information you’re looking for, the more incidents may accumulate between reviews to split attention, and the more likely you are to forget older incidents.
- Review prioritization: When you use analysis tools, how clear are your search priorities? Patterns are easiest to spot...