Directory Service Event Log Monitoring Checklist Form
Use this checklist to assess your directory service event log monitoring practices. Review each item to ensure effective oversight and compliance.
How frequently are directory service event logs reviewed?
*
Daily
Weekly
Monthly
Rarely/Never
Are alerts configured for critical directory service events?
*
Yes
No
Partially
Which types of critical events are actively monitored?
*
Authentication failures
Privilege changes
Account lockouts
Group membership changes
Other
Is there a documented procedure for event log review?
*
Yes
No
How long are event logs retained?
*
Less than 30 days
30-90 days
91-180 days
More than 180 days
Rate the effectiveness of current event log monitoring tools.
*
1
2
3
4
5
Has a recent audit found any issues with directory service log monitoring?
*
No issues found
Minor issues
Major issues
No recent audit conducted
Indicate your level of agreement with the following: 'Event log monitoring is prioritized by management.'
*
Strongly Disagree
1
2
3
4
Strongly Agree
5
1 is Strongly Disagree, 5 is Strongly Agree
Who is responsible for reviewing directory service event logs?
*
Please Select
IT Security Team
System Administrators
External Auditors
Other
Event Log Review Summary
Submit Checklist
Should be Empty: