The organization must log admin and security logs from used devices and services.
These logs record actions taken by system administrators and privileged users. They help monitor changes to system configurations, user access rights, and other critical settings. By keeping these logs, an organization can audit administrative activities and ensure accountability.
Security logs capture events related to the security of systems and data. This includes login attempts, firewall activities, intrusion detection system alerts, and antivirus actions. Monitoring these logs helps identify suspicious activities that could indicate a security breach or an internal threat.