Today, CISA released the Microsoft Expanded Cloud Logs Implementation Playbook to help organizations get the most out of Microsoft’s newly introduced logs in Microsoft Purview Audit (Standard). This step-by-step guide enables technical personnel to better detect and defend against advanced intrusion techniques by operationalizing expanded cloud logs. 

The playbook details analytical methodologies tied to using these logs. Specifically, the playbook offers:

  • An overview of the newly introduced logs in Microsoft Purview Audit (Standard) that enable organizations to conduct forensic and compliance investigations by accessing critical events (e.g., mail items accessed, mail items sent, and user searches in SharePoint Online and Exchange Online).
  • A description of administration/enabling actions and ingestion of these logs to Microsoft Sentinel and Splunk Security Information and Event Management (SIEM) systems.
  • A discussion of significant events in other M365 services, such as Teams.

CISA encourages organizations to use the playbook to make newly available logs an actionable part of their enterprise cybersecurity operations. 



Source link

admin

Share
Published by
admin

Recent Posts

Fortinet Releases Security Updates for Multiple Products

Fortinet released security updates to address vulnerabilities in multiple Fortinet products. A cyber threat actor…

1 day ago

CISA and US and International Partners Publish Guidance on Priority Considerations in Product Selection for OT Owners and Operators

Today, CISA—along with U.S. and international partners—released joint guidance Secure by Demand: Priority Considerations for…

2 days ago

CISA Releases Two Industrial Control Systems Advisories

CISA released two Industrial Control Systems (ICS) advisories on January 7, 2025. These advisories provide…

3 days ago

CISA Releases Four Industrial Control Systems Advisories

CISA released four Industrial Control Systems (ICS) advisories on January 10, 2025. These advisories provide…

4 days ago

CISA Releases the Cybersecurity Performance Goals Adoption Report

Today, CISA released the Cybersecurity Performance Goals Adoption Report to highlight how adoption of Cybersecurity…

5 days ago

Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways

Ivanti released security updates to address vulnerabilities (CVE-2025-0282, CVE-2025-0283) in Ivanti Connect Secure, Policy Secure,…

6 days ago

This website uses cookies.