Cyber Prepared
← Cloud Security
Version 2.0Updated Jun 19, 2026

Cloud Logging & Detection Baseline

Build a cloud logging baseline that starts with investigation questions instead of vendor checkboxes. This guide maps high-value event sources to detection and response use cases, defines retention tiers, and gives teams a validation routine for proving critical telemetry is complete.

loggingdetectiontelemetrycloud
Inside the document
  1. 01Investigation question map
  2. 02Required identity events
  3. 03Control-plane telemetry
  4. 04Retention and integrity tiers
  5. 05Quarterly validation routine

Collect what responders will need

Each source is tied to a concrete investigation question, making coverage gaps easier to explain and prioritize.

Provider-neutral by design

The control language works across major cloud platforms while leaving room for provider-specific implementation notes.