Closely monitoring a CDS is key to maintaining the security of the solution and the integrity of the information it protects. A CDS should provide audit information to an organisation's Security Information and Event Monitoring system (SIEM).
Defensive techniques
Monitoring should be in place in a number of key areas:
Any changes to the system configuration should be monitored.
All exports from the system should be monitored to look for unauthorised exports and to clarify what data has been ex-filtrated in the event of a compromise.
All imports to the system should be monitored to look for malicious content.
Errors and failures of components within the system should be monitored to identify potential attacks.
Monitoring the process execution within software components that handle complex data should look for unusual behaviour, which could indicate an attack.
Network monitoring is recommended on the external boundary, to detect inbound connections from unknown sources.
Network monitoring is recommended on the internal network, to detect unauthorised outbound connection attempts. This could indicate a compromised host within the internal network.