Best Practices on OCI Part 3: Logging & Monitoring
Amrita Mukherjee, CCSP
Cloud Whisperer. Security Savant. Super Mom. cloudgal42.com
Here are some key recommendations for configuring logging and monitoring on Oracle Cloud Infrastructure -
- Ensure audit log retention period is set to 365 days - Log retention controls how long activity logs should be retained. Studies have shown that The Mean Time to Detect(MTTD) a cyber breach is anywhere from 30 days in some sectors to up to 206 days in others. Retaining logs for at least 365 days or more will provide the ability to respond to incidents.
- Ensure default tags are used on resources - In the case of an incident having default tags like “CreatedBy” applied will provide info on who created the resource without having to search the Audit logs.
Continue reading here