Skip to main content
Guidance

Securing HTTP-based APIs

How to ensure that application programming interfaces are designed and built securely.

Page 7 of 8

6. Logging and monitoring

On this page
  1. Logging
  2. Monitoring

Logging and monitoring, while closely related and often used together, serve different purposes. Logging is retrospective, providing a comprehensive audit trail that can be used for troubleshooting, forensic analysis, compliance audits, and incident response. It focuses on storing information for later review and analysis. Monitoring, on the other hand, involves the continuous, real-time observation and analysis of system behaviour, performance metrics, and security indicators.

Best practices for logging and monitoring focus on detecting, investigating and responding to potential threats while maintaining compliance and performance. If you are not sure what you should be logging, please refer to the following NCSC guidance which explains what data to collect for security purposes and when to collect it.



Published

Reviewed

Version

1.0