I've come to the point where I need to begin looking at logging for ISO 27001 compliance.
Budgets are tight (aren't they always!) but I'm thinking the easiest way is to use some form of syslog server in our Windows domain based environment and regularly review the most frequent or critical events logged?
Has anyone done this recently? Ideally looking at open source, free solutions to make our compliance lives just that little bit easier?
Budgets are tight (aren't they always!) but I'm thinking the easiest way is to use some form of syslog server in our Windows domain based environment and regularly review the most frequent or critical events logged?
Has anyone done this recently? Ideally looking at open source, free solutions to make our compliance lives just that little bit easier?

its all about scaling out these days. however for ref I cant remember the specs but its not a lot, something along the lines of 4gb ram, 2 ancient xeon cores and raid10 local storage.


