Guidance
Design and build a privately hosted Public Key Infrastructure
Principles for the design and build of in-house Public Key Infrastructure (PKI)
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 18 of 21
CA logs should be exported in real time to a central logging facility, to give full visibility of PKI operations.
What to watch
Some example areas of interest for your monitoring solutions are:
This is not an exhaustive list. You may find there are certain areas that are relevant to your environment that you need to log and monitor for.
Monitoring goals
The purpose of the monitoring system is to alert you and your organisation to the following:
Access to theses logs should be limited to individuals that require access. Write permission should be limited, and you should have measures in place to detect changes in the logs.


