According to NIST, if the audit trails you are providing are being used properly to record the right information, they should also be useful in intrusion detection. Whether it is through your audit trails or your other alerts, having processes that can detect intrusions is a vital resource for preventing damage to your organization. Usually, intruders won’t find exactly what they’re looking for when they enter your system. Detecting and removing them as soon as possible could prevent any data from being compromised. Failing to do so could give intruders months to move around your network looking for valuable data.
4) Problem identification through auditing and monitoring
Data breaches and cyber-attacks aren’t the only problems a business faces. Your security tools can also be used to help identify problems like changes in coding, broken integrations, or other problems in your system. Being able to leverage your auditing and monitoring can help find the root-cause of a problem and get it fixed much quicker.