07.07.2015 Views

Cyber-Security-Monitoring-Guide

Cyber-Security-Monitoring-Guide

Cyber-Security-Monitoring-Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Cyber</strong> <strong>Security</strong> <strong>Monitoring</strong> and Logging <strong>Guide</strong>Important - priority 2Cost Collect Retain Monitor Analyse RespondSystem activity logs (eg Admin) Free 63% 56% 59% 37% 29%Firewall Free 66% 51% 56% 34% 34%DNS Free 46% 37% 41% 17% 15%DHCP Free 44% 24% 29% 17% 15%Web Server logs Free 49% 29% 37% 20% 12%SQL server logs Free 44% 29% 34% 10% 10%Sandboxing techniques (including vitualexecution engines)£££ 27% 22% 32% 29% 15%Useful - priority 3Cost Collect Retain Monitor Analyse RespondEndpoint (and agent-based) logs £ 49% 44% 49% 27% 24%Authentication logs (eg Windows) Free 56% 51% 49% 32% 29%Physical ££ 44% 37% 32% 24% 17%VPN Free 61% 49% 44% 22% 27%Netflow Free 34% 24% 29% 10% 17%FTP Free 37% 22% 27% 7% 10%Appflow Free 17% 12% 17% 5% 2%Data loss protection (DLP) ££ 24% 22% 32% 24% 27%!Costs cover purchase and ongoing cost of any relevant tools and services, but excluderesourcing. Logs marked in the cost column as ‘None’ should be freely available unlessyou are using outsourcers or MSSPs.No logs are completely free as they will all involve some cost (eg. to obtain, store andanalyse) - but those marked as free are already ‘baked-in’ to systems, networks, toolsor services that your organisations has already paid for.Whilst this analysis should be very useful for many organisations, these logs are only the ones that workshop participantsbelieved could typically be categorised in these ways.In practice, the importance, cost and use of these logs may differ considerably for any given organisation, for examplebased on the type of organisation, the nature of their business, and their maturity in cyber security. Consequently, logmanagement will need to be evaluated on a case-by-case basis.21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!