{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/enterprise-log-management-policy/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/enterprise-log-management-policy/",
        "slug": "enterprise-log-management-policy",
        "url": "https://update.dsesecurity.com/updates/enterprise-log-management-policy/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/enterprise-log-management-policy.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/enterprise-log-management-policy/"
        },
        "title": "Create an enterprise log-management policy before choosing a SIEM",
        "summary": "NIST’s durable log-management structure starts with policy, organization-wide responsibility, infrastructure, operating processes, and supported staff—not a particular analytics product.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-19T21:26:27+00:00",
        "modified_at": "2026-07-19T21:26:27+00:00",
        "reviewed_on": "2026-07-19",
        "reading_minutes": 2,
        "word_count": 377,
        "potentially_affected": "Security, IT, application, records, privacy, compliance, and business teams responsible for creating, transporting, storing, reviewing, retaining, or disposing of log data.",
        "dse_recommendation": "Assign responsibilities, define requirements by system class, establish secure lifecycle processes, prioritize review, support operators, and audit whether logs remain complete and usable.",
        "primary_source": {
            "name": "NIST SP 800-92: Guide to Computer Security Log Management",
            "url": "https://csrc.nist.gov/pubs/sp/800/92/final",
            "published_on": "2006-09-13",
            "authority": "National Institute of Standards and Technology"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<article>\n  <p class=\"lede\">A security information and event management platform cannot decide which records the organization needs, who is permitted to access them, how long they remain useful, or what happens when collection fails. Those are governance and operating decisions.</p>\n\n  <h2>NIST&#8217;s program-level foundation</h2>\n  <p><strong>Source fact:</strong> NIST SP 800-92 provides high-level guidance for developing, implementing, and maintaining effective log-management practices across an enterprise. It addresses policy and procedures, log-management infrastructure, organization-wide processes, and support for personnel with log responsibilities.</p>\n  <p><strong>Source fact:</strong> The publication discusses the lifecycle of generating, transmitting, storing, accessing, analyzing, and disposing of log data. NIST notes that logs support security-incident identification and investigation, operational problem solving, and retention needs. It explicitly does not provide step-by-step instructions for a particular logging technology.</p>\n\n  <h2>Write requirements that systems can implement</h2>\n  <p><strong>DSE recommendation:</strong> define requirements by system and data class. A policy should state:</p>\n  <ul>\n    <li>the security, operational, legal, contractual, and records purposes for collection;</li>\n    <li>minimum event types and context, time synchronization, and expected source reliability;</li>\n    <li>approved collection paths, protection in transit and storage, and recovery expectations;</li>\n    <li>roles allowed to configure, access, analyze, export, preserve, and dispose of records;</li>\n    <li>retention and disposal authority, including preservation when an incident or legal hold applies;</li>\n    <li>monitoring for collection failure, capacity exhaustion, time drift, and unauthorized change.</li>\n  </ul>\n\n  <p><strong>DSE recommendation:</strong> assign executive, security, operations, application, privacy, and records responsibilities without assuming one team can own every decision. Standardize common requirements, but document justified differences for specialized, cloud, mobile, legacy, or operational systems.</p>\n\n  <h2>Operate and audit the lifecycle</h2>\n  <p>Prioritize sources and review frequency according to risk and available capacity. Give responsible staff procedures, training, tools, escalation paths, and protected time to perform the work. Periodically test whether required events are generated, transported, searchable, time-aligned, access-controlled, retained, recoverable, and disposed of as approved. Measure missing sources and unusable events, not only storage volume.</p>\n\n  <h2>Applicability and limits</h2>\n  <p>SP 800-92 was published in 2006, and its technology examples and legal references are old. As of this review, NIST SP 800-92 Rev. 1 remains an initial public draft, not a final controlling publication. Use the 2006 final for durable program structure and current CISA event-logging guidance for modern operational emphasis. Current law, contracts, privacy obligations, and platform documentation must determine implementation and retention.</p>\n\n  <h2>Official reference</h2>\n  <p><a href=\"https://csrc.nist.gov/pubs/sp/800/92/final\" target=\"_blank\" rel=\"noopener noreferrer\">NIST SP 800-92</a> — final NIST guidance on enterprise computer-security log management.</p>\n</article>",
        "content_text": "A security information and event management platform cannot decide which records the organization needs, who is permitted to access them, how long they remain useful, or what happens when collection fails. Those are governance and operating decisions.\n\n NIST’s program-level foundation\n Source fact: NIST SP 800-92 provides high-level guidance for developing, implementing, and maintaining effective log-management practices across an enterprise. It addresses policy and procedures, log-management infrastructure, organization-wide processes, and support for personnel with log responsibilities.\n Source fact: The publication discusses the lifecycle of generating, transmitting, storing, accessing, analyzing, and disposing of log data. NIST notes that logs support security-incident identification and investigation, operational problem solving, and retention needs. It explicitly does not provide step-by-step instructions for a particular logging technology.\n\n Write requirements that systems can implement\n DSE recommendation: define requirements by system and data class. A policy should state:\n \n the security, operational, legal, contractual, and records purposes for collection;\n minimum event types and context, time synchronization, and expected source reliability;\n approved collection paths, protection in transit and storage, and recovery expectations;\n roles allowed to configure, access, analyze, export, preserve, and dispose of records;\n retention and disposal authority, including preservation when an incident or legal hold applies;\n monitoring for collection failure, capacity exhaustion, time drift, and unauthorized change.\n \n\n DSE recommendation: assign executive, security, operations, application, privacy, and records responsibilities without assuming one team can own every decision. Standardize common requirements, but document justified differences for specialized, cloud, mobile, legacy, or operational systems.\n\n Operate and audit the lifecycle\n Prioritize sources and review frequency according to risk and available capacity. Give responsible staff procedures, training, tools, escalation paths, and protected time to perform the work. Periodically test whether required events are generated, transported, searchable, time-aligned, access-controlled, retained, recoverable, and disposed of as approved. Measure missing sources and unusable events, not only storage volume.\n\n Applicability and limits\n SP 800-92 was published in 2006, and its technology examples and legal references are old. As of this review, NIST SP 800-92 Rev. 1 remains an initial public draft, not a final controlling publication. Use the 2006 final for durable program structure and current CISA event-logging guidance for modern operational emphasis. Current law, contracts, privacy obligations, and platform documentation must determine implementation and retention.\n\n Official reference\n NIST SP 800-92 — final NIST guidance on enterprise computer-security log management.",
        "content_markdown": "A security information and event management platform cannot decide which records the organization needs, who is permitted to access them, how long they remain useful, or what happens when collection fails. Those are governance and operating decisions.\n\n## NIST’s program-level foundation\n\nSource fact: NIST SP 800-92 provides high-level guidance for developing, implementing, and maintaining effective log-management practices across an enterprise. It addresses policy and procedures, log-management infrastructure, organization-wide processes, and support for personnel with log responsibilities.\n\nSource fact: The publication discusses the lifecycle of generating, transmitting, storing, accessing, analyzing, and disposing of log data. NIST notes that logs support security-incident identification and investigation, operational problem solving, and retention needs. It explicitly does not provide step-by-step instructions for a particular logging technology.\n\n## Write requirements that systems can implement\n\nDSE recommendation: define requirements by system and data class. A policy should state:\n\n- the security, operational, legal, contractual, and records purposes for collection;\n\n- minimum event types and context, time synchronization, and expected source reliability;\n\n- approved collection paths, protection in transit and storage, and recovery expectations;\n\n- roles allowed to configure, access, analyze, export, preserve, and dispose of records;\n\n- retention and disposal authority, including preservation when an incident or legal hold applies;\n\n- monitoring for collection failure, capacity exhaustion, time drift, and unauthorized change.\n\nDSE recommendation: assign executive, security, operations, application, privacy, and records responsibilities without assuming one team can own every decision. Standardize common requirements, but document justified differences for specialized, cloud, mobile, legacy, or operational systems.\n\n## Operate and audit the lifecycle\n\nPrioritize sources and review frequency according to risk and available capacity. Give responsible staff procedures, training, tools, escalation paths, and protected time to perform the work. Periodically test whether required events are generated, transported, searchable, time-aligned, access-controlled, retained, recoverable, and disposed of as approved. Measure missing sources and unusable events, not only storage volume.\n\n## Applicability and limits\n\nSP 800-92 was published in 2006, and its technology examples and legal references are old. As of this review, NIST SP 800-92 Rev. 1 remains an initial public draft, not a final controlling publication. Use the 2006 final for durable program structure and current CISA event-logging guidance for modern operational emphasis. Current law, contracts, privacy obligations, and platform documentation must determine implementation and retention.\n\n## Official reference\n\n[NIST SP 800-92](https://csrc.nist.gov/pubs/sp/800/92/final) — final NIST guidance on enterprise computer-security log management."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/enterprise-log-management-policy/",
                "url": "https://update.dsesecurity.com/updates/enterprise-log-management-policy/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-19"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/enterprise-log-management-policy/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Create an enterprise log-management policy before choosing a SIEM",
                        "item": "https://update.dsesecurity.com/updates/enterprise-log-management-policy/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/enterprise-log-management-policy/#article",
                "identifier": "https://update.dsesecurity.com/updates/enterprise-log-management-policy/",
                "url": "https://update.dsesecurity.com/updates/enterprise-log-management-policy/",
                "headline": "Create an enterprise log-management policy before choosing a SIEM",
                "description": "NIST’s durable log-management structure starts with policy, organization-wide responsibility, infrastructure, operating processes, and supported…",
                "abstract": "NIST’s durable log-management structure starts with policy, organization-wide responsibility, infrastructure, operating processes, and supported staff—not a particular analytics product.",
                "articleBody": "A security information and event management platform cannot decide which records the organization needs, who is permitted to access them, how long they remain useful, or what happens when collection fails. Those are governance and operating decisions.\n\n NIST’s program-level foundation\n Source fact: NIST SP 800-92 provides high-level guidance for developing, implementing, and maintaining effective log-management practices across an enterprise. It addresses policy and procedures, log-management infrastructure, organization-wide processes, and support for personnel with log responsibilities.\n Source fact: The publication discusses the lifecycle of generating, transmitting, storing, accessing, analyzing, and disposing of log data. NIST notes that logs support security-incident identification and investigation, operational problem solving, and retention needs. It explicitly does not provide step-by-step instructions for a particular logging technology.\n\n Write requirements that systems can implement\n DSE recommendation: define requirements by system and data class. A policy should state:\n \n the security, operational, legal, contractual, and records purposes for collection;\n minimum event types and context, time synchronization, and expected source reliability;\n approved collection paths, protection in transit and storage, and recovery expectations;\n roles allowed to configure, access, analyze, export, preserve, and dispose of records;\n retention and disposal authority, including preservation when an incident or legal hold applies;\n monitoring for collection failure, capacity exhaustion, time drift, and unauthorized change.\n \n\n DSE recommendation: assign executive, security, operations, application, privacy, and records responsibilities without assuming one team can own every decision. Standardize common requirements, but document justified differences for specialized, cloud, mobile, legacy, or operational systems.\n\n Operate and audit the lifecycle\n Prioritize sources and review frequency according to risk and available capacity. Give responsible staff procedures, training, tools, escalation paths, and protected time to perform the work. Periodically test whether required events are generated, transported, searchable, time-aligned, access-controlled, retained, recoverable, and disposed of as approved. Measure missing sources and unusable events, not only storage volume.\n\n Applicability and limits\n SP 800-92 was published in 2006, and its technology examples and legal references are old. As of this review, NIST SP 800-92 Rev. 1 remains an initial public draft, not a final controlling publication. Use the 2006 final for durable program structure and current CISA event-logging guidance for modern operational emphasis. Current law, contracts, privacy obligations, and platform documentation must determine implementation and retention.\n\n Official reference\n NIST SP 800-92 — final NIST guidance on enterprise computer-security log management.",
                "datePublished": "2026-07-19T21:26:27+00:00",
                "dateModified": "2026-07-19T21:26:27+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/enterprise-log-management-policy/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 377,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "NIST SP 800-92: Guide to Computer Security Log Management",
                    "url": "https://csrc.nist.gov/pubs/sp/800/92/final",
                    "datePublished": "2006-09-13"
                }
            }
        ]
    }
}