Log Management
What is Log Management?
The process of collecting, aggregating, storing, and analysing log data from various sources across an IT environment. Log management supports security monitoring, compliance reporting, and incident investigation.
Terms that appear alongside log management
Each of these is named in at least one of the same controls as log management. The number is how many controls name both.
- audit 11 shared controls
- nist 9 shared controls
- integrity 8 shared controls
- log retention 6 shared controls
- security monitoring 5 shared controls
- incident response 5 shared controls
- authentication 5 shared controls
- audit log 5 shared controls
Frameworks that govern log management
What the standards actually require on log management
Requirements naming log management across 6 standards, quoted from the control text.
Establish a log management programme per NIST SP 800-92 Chapter 2 (Introduction to Computer Security Log Management) + Chapter 4 (Log Management Planning).
NISTSP92-1 · Log Management Programme, Policy, Roles, and Operational Runbooks →Establish and maintain an audit log management process that defines the enterprise’s logging requirements. At a minimum, address the collection, review, and retention of audit logs for enterprise assets.
CIS-8.1 · Establish and Maintain an Audit Log Management Process →Aggregate security logs in Microsoft Sentinel or equivalent SIEM with documented detection rules and analyst workflows.
LT-5 · Centralize security log management and analysis →Implement security monitoring including IDS/IPS, SIEM, and log analysis. Retain security logs for at least 1 year. Review logs regularly for anomalies.
ISMSP-SYS-03 · Security Monitoring and Log Management →ICT systems must implement event logging and log management sufficient to detect and investigate security events.
DSPF-P20 · Information and technology security - logging and monitoring →Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. NIST recommends central log management aligned to SP 800-92.
164.312(b) · Audit Controls (Standard) →Questions people ask about log management
What is Log Management?
Why is Log Management important for compliance?
Which compliance frameworks address Log Management?
Where can I learn more about Log Management?
See how Log Management applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.