Create an enterprise log-management policy before choosing a SIEM

NIST’s durable log-management structure starts with policy, organization-wide responsibility, infrastructure, operating processes, and supported staff—not a particular analytics product.

Executive summary

What you need to know

NIST’s durable log-management structure starts with policy, organization-wide responsibility, infrastructure, operating processes, and supported staff—not a particular analytics product.

Potentially affected

Security, IT, application, records, privacy, compliance, and business teams responsible for creating, transporting, storing, reviewing, retaining, or disposing of log data.

DSE recommendation

Assign responsibilities, define requirements by system class, establish secure lifecycle processes, prioritize review, support operators, and audit whether logs remain complete and usable.

A security information and event management platform cannot decide which records the organization needs, who is permitted to access them, how long they remain useful, or what happens when collection fails. Those are governance and operating decisions.

NIST’s program-level foundation

Source fact: NIST SP 800-92 provides high-level guidance for developing, implementing, and maintaining effective log-management practices across an enterprise. It addresses policy and procedures, log-management infrastructure, organization-wide processes, and support for personnel with log responsibilities.

Source fact: The publication discusses the lifecycle of generating, transmitting, storing, accessing, analyzing, and disposing of log data. NIST notes that logs support security-incident identification and investigation, operational problem solving, and retention needs. It explicitly does not provide step-by-step instructions for a particular logging technology.

Write requirements that systems can implement

DSE recommendation: define requirements by system and data class. A policy should state:

  • the security, operational, legal, contractual, and records purposes for collection;
  • minimum event types and context, time synchronization, and expected source reliability;
  • approved collection paths, protection in transit and storage, and recovery expectations;
  • roles allowed to configure, access, analyze, export, preserve, and dispose of records;
  • retention and disposal authority, including preservation when an incident or legal hold applies;
  • monitoring for collection failure, capacity exhaustion, time drift, and unauthorized change.

DSE recommendation: assign executive, security, operations, application, privacy, and records responsibilities without assuming one team can own every decision. Standardize common requirements, but document justified differences for specialized, cloud, mobile, legacy, or operational systems.

Operate and audit the lifecycle

Prioritize sources and review frequency according to risk and available capacity. Give responsible staff procedures, training, tools, escalation paths, and protected time to perform the work. Periodically test whether required events are generated, transported, searchable, time-aligned, access-controlled, retained, recoverable, and disposed of as approved. Measure missing sources and unusable events, not only storage volume.

Applicability and limits

SP 800-92 was published in 2006, and its technology examples and legal references are old. As of this review, NIST SP 800-92 Rev. 1 remains an initial public draft, not a final controlling publication. Use the 2006 final for durable program structure and current CISA event-logging guidance for modern operational emphasis. Current law, contracts, privacy obligations, and platform documentation must determine implementation and retention.

Official reference

NIST SP 800-92 — final NIST guidance on enterprise computer-security log management.

Primary reference

Review the official source

NIST SP 800-92: Guide to Computer Security Log Management · Published September 13, 2006

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE