https://www.splunk.com/en_us/blog/learn/log-management.html
In this introductory guide, Splunk emphasizes the importance of log management for businesses of all sizes. It highlights that understanding logs is essential for effectively resolving errors and failures. The guide concludes by addressing the question, "What does log management actually mean?"
https://www.techtarget.com/searchsecurity/tip/Security-log-management-and-logging-best-practices
Learn how to conduct security log management that provides visibility into IT infrastructure activities and traffic, improves troubleshooting and prevents service disruptions.
https://security.berkeley.edu/security-audit-logging-guideline
This guideline describes the risk of inadequate logging, defines events to be logged and establishes a case for using an automated tool for log review.
US-CERT – CRR Supplemental Resource Guide, Volume 5: Incident Management
3.3 3.3.5 Audit and Accountability
https://www.cisa.gov/uscert/sites/default/files/c3vp/crr_resources_guides/CRR_Resource_Guide-IM.pdf
US-CERT resource that provides information on how to create, test and improve an Incident Management plan.
https://wrightbrainedsecurity.com/signal-not-noise-au-3-3-3/
This blog posts discusses AU 3.3.3.
https://www.youtube.com/watch?v=Fo33lEWkqO4&list=PLstjectj9BFgWGjHn4y2oygN34oFpSPjR&index=56
In this video, Mike dives into CMMC 2.0 Control IR.L2-3.6.1. This control is all about being prepared, having a written and practiced plan in place so that your entire team knows exactly what to do when an attack happens.
YouTube – CMMC 2.0 Control AU.L2-3.3.4 – Alert in the Event of an Audit Logging Process Failure
3.3 3.3.4 Audit and Accountability
https://www.youtube.com/watch?v=69uZ6j9Fdgg
This video provides an in-depth explanation of alerting in the event of an audit logging process failure.
https://www.youtube.com/watch?v=0T90PfC3H6A
In this edition of the On Call Compliance Solutions discuss how to move from data overload to data on demand and proactive reporting.
YouTube – CMMC AU.L2-3.3.7 – If Your Clocks Are Off, Your Audit Is Too
3.3 3.3.7 Audit and Accountability
https://www.youtube.com/watch?v=UBqTrFbrrqk
Ever try to investigate an incident using logs that aren’t synced? It’s like trying to solve a mystery with the pages out of order. In this video, we tackle CMMC Control AU.L2-3.3.7, which requires all your systems to sync to an authoritative time source—so your audit records are accurate, aligned, and admissible.
https://www.youtube.com/watch?v=N2ixPAuymZQ
If everyone can manage your logs, no one is really accountable—and your CMMC assessor will definitely notice. This video covers how to comply with CMMC Control AU.L2-3.3.9, which is all about restricting audit logging privileges to a trusted few.