Skip to main content
Guidance

Building a Security Operations Centre (SOC)

Designing a security monitoring capability proportionate to the threats faced (and resources available).

Page 7 of 14

Log sources

Identify log sources that will provide you with information that would be useful when performing security monitoring.

Having followed the principles set out in the Operating Model page, you should have a fairly comprehensive understanding of your system and its architecture. You should also have an idea of the threat and sophistication of attack that you are trying to detect within your system.

The next step is to identify log sources within your organisation (or customer systems) that will provide you with information that would be useful when performing security monitoring. This is where threat modelling can be useful, as it will enable you to identify valuable log sources and provide a rationale as to why you should collect them.

In addition to being used for detection, log sources are also vital in performing incident response as they can provide valuable context around system behaviour in the event of an incident.



Published

Reviewed

Version

1.0