Logs generally contain information pertaining to security management and are generated through different sources including firewalls, anti-malware systems, routers, switches, applications and operating systems. It is rather unfortunate that many small businesses tend to ignore the logs till a security problem arises. Regular log reviews are helpful in identifying security incidents and detecting all lapses like policy violations, fraudulent activity, and operational problems soon after they have occurred.
There is no denying the fact that today there is a widespread deployment of networked servers, workstations, and other computer devices. This has led to a commensurate increase in the number of threats to networks and systems, necessitating an effective computer security log management. The purpose of computer security log management is to generate, transmit, store, and analyze computer security log data. Security log management facilitates storage of computer security records in adequate detail for any prescribed period of time.
One of the main reasons for enabling logs beyond compliance reasons is to maintain accountability. Logs and log monitoring tools enable the business to trace actions after they have occurred. Preventative controls such as authentication and encryption can always fail, and logs capture the actions and act as detective controls. This enables the business to pursue the actions of their users if there is a breach and pursue legal action if need be.
Many would quickly assume that log management is a detective control, but that doesn't mean it can't be a proactive measure. Log review or monitoring of outliers in log output can help identify possible threats that recently occurred. It allows questions to be asked early on, in pursuit of suspicious activity.