Log scope design
Collecting everything is costly and noisy. Together we decide which record from which source is kept for how long, based on your threat scenarios and regulatory needs.
For organisations with many systems, several teams and a need to report to the board. The scope of log sources, analyst tiers, response authority and governance are designed with you and written into the contract.
Collecting everything is costly and noisy. Together we decide which record from which source is kept for how long, based on your threat scenarios and regulatory needs.
The first tier filters the alert, the second investigates the incident in depth, the third does threat hunting and rule development. The conditions under which an incident is escalated are written down.
Who decides what is gathered in a responsibility matrix. Regular management meetings, measured indicators and an annual exercise plan are part of the service.
Four stops, four responsibilities: each has a clear owner and a clear output.
We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.
Each step ends with something concrete in your hands; we move on with your approval.
Together we put the goal, the boundaries and the acceptance criteria in writing.
We set up tools, access and settings, document the setup and hand it over to you.
We watch the agreed indicators regularly and notify you when something deviates.
We share what was done, the result and the next step in a plain report.
What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.
Tell us what you need; we will define the scope together.
Tell us about your projectYes. The analyst team covers working hours and an on-call expert looks at alerts outside them. The shift pattern, team size and response times are written into the contract.
Yes. Only systems you are authorised for and have approved in writing are assessed.
Scope, time window and methods are agreed in advance; risky steps require your separate approval.
Tell us what you need; we will define the scope together.