Terminology Index

Glossary

1801 terms

Open concept maps

Showing 321-352 of 1801 terms

C
32

Cloud Log Preservation

Ensuring cloud logs needed for an investigation are captured, retained, and protected from deletion or tampering, including before an incident, since many cloud logs are off by default or expire quickly and cannot be recovered once gone.

Cloud evidence is fragile: audit logging may be disabled, retention windows may be short, and an attacker may try to delete logs. Preservation means enabling the right logs in advance, setting adequate retention, centralizing them where the attacker cannot reach, and protecting their integrity. Without it, an investigation can be blind to exactly the period that matters, so preservation is a prerequisite that must be in place before, not during, an incident.

Introduced in: Cloud Incident Response

Examples

  • Enabling and centralizing audit logs ahead of any incident so evidence exists.
  • Setting log retention long enough to cover an attacker's dwell time.
  • Storing logs in an account the attacker cannot access or delete.

No related terms linked yet.