# Create an enterprise log-management policy before choosing a SIEM

> NIST’s durable log-management structure starts with policy, organization-wide responsibility, infrastructure, operating processes, and supported staff—not a particular analytics product.

- Canonical URL: https://update.dsesecurity.com/updates/enterprise-log-management-policy/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-07-19T21:26:27+00:00
- Modified: 2026-07-19T21:26:27+00:00
- Last reviewed by DSE: 2026-07-19
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

NIST’s durable log-management structure starts with policy, organization-wide responsibility, infrastructure, operating processes, and supported staff—not a particular analytics product.

## Potentially affected

Security, IT, application, records, privacy, compliance, and business teams responsible for creating, transporting, storing, reviewing, retaining, or disposing of log data.

## DSE recommendation

Assign responsibilities, define requirements by system class, establish secure lifecycle processes, prioritize review, support operators, and audit whether logs remain complete and usable.

## Article

A security information and event management platform cannot decide which records the organization needs, who is permitted to access them, how long they remain useful, or what happens when collection fails. Those are governance and operating decisions.

## NIST’s program-level foundation

Source fact: NIST SP 800-92 provides high-level guidance for developing, implementing, and maintaining effective log-management practices across an enterprise. It addresses policy and procedures, log-management infrastructure, organization-wide processes, and support for personnel with log responsibilities.

Source fact: The publication discusses the lifecycle of generating, transmitting, storing, accessing, analyzing, and disposing of log data. NIST notes that logs support security-incident identification and investigation, operational problem solving, and retention needs. It explicitly does not provide step-by-step instructions for a particular logging technology.

## Write requirements that systems can implement

DSE recommendation: define requirements by system and data class. A policy should state:

- the security, operational, legal, contractual, and records purposes for collection;

- minimum event types and context, time synchronization, and expected source reliability;

- approved collection paths, protection in transit and storage, and recovery expectations;

- roles allowed to configure, access, analyze, export, preserve, and dispose of records;

- retention and disposal authority, including preservation when an incident or legal hold applies;

- monitoring for collection failure, capacity exhaustion, time drift, and unauthorized change.

DSE recommendation: assign executive, security, operations, application, privacy, and records responsibilities without assuming one team can own every decision. Standardize common requirements, but document justified differences for specialized, cloud, mobile, legacy, or operational systems.

## Operate and audit the lifecycle

Prioritize sources and review frequency according to risk and available capacity. Give responsible staff procedures, training, tools, escalation paths, and protected time to perform the work. Periodically test whether required events are generated, transported, searchable, time-aligned, access-controlled, retained, recoverable, and disposed of as approved. Measure missing sources and unusable events, not only storage volume.

## Applicability and limits

SP 800-92 was published in 2006, and its technology examples and legal references are old. As of this review, NIST SP 800-92 Rev. 1 remains an initial public draft, not a final controlling publication. Use the 2006 final for durable program structure and current CISA event-logging guidance for modern operational emphasis. Current law, contracts, privacy obligations, and platform documentation must determine implementation and retention.

## Official reference

[NIST SP 800-92](https://csrc.nist.gov/pubs/sp/800/92/final) — final NIST guidance on enterprise computer-security log management.

## Primary reference

- Name: NIST SP 800-92: Guide to Computer Security Log Management
- Authority: National Institute of Standards and Technology
- URL: https://csrc.nist.gov/pubs/sp/800/92/final
- Source publication date: 2006-09-13

## Citation and use

Preferred citation: “Create an enterprise log-management policy before choosing a SIEM,” DSE Security, https://update.dsesecurity.com/updates/enterprise-log-management-policy/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
