Discussion about this post

User's avatar
Marius Laurusevicius's avatar

The split between a log and a decision input is still unfinished in the standards layer. NIST SP 800-92 Rev. 1, the Cybersecurity Log Management Planning Guide by Karen Scarfone and Murugiah Souppaya, appeared as an initial public draft on 11 October 2023, its comment period closed on 29 November 2023, and the document history lists no final version since. Its definition of log management covers generating, transmitting, storing, accessing and disposing of log data, so disposal is part of the job rather than cleanup afterwards. That is the same boundary drawn here between a record and an instruction.

No posts

Ready for more?