πΌ Management Samenvatting
Azure monitoren architecture centraliseert metrics, logt en traces van Azure resources, applications en infrastructure voor observability, alerting, diagnostics en security monitoring via loggen Analytics workspaces en Application Insights.
Zonder monitoring: blind to performance issues, beveiligingsincidenten undetected, no troubleshooting data, compliance hiaten (logging requirements). Azure monitoren provides: Centralized logging (all Azure resources), Metrics collection (performance, health), Alerting (proactive issue detectie), Workbooks (visualization), Integration (Sentinel SIEM, automation).
Implementatie
Azure monitoren architecture: (1) loggen Analytics Workspaces: Central loggen repository, KQL queries, retentiebeleid (30-730 days), Multiple workspaces (per environment/region); (2) Diagnostic Settings: Resource logt β workspace, Activity logt β workspace, Metrics β workspace; (3) Alerts: Metric alerts (CPU >80%), loggen query alerts (error patterns), Activity loggen alerts (resource deletions); (4) Action Groups: Email, SMS, webhook, Logic App triggers; (5) Application Insights: APM (Application Performance monitoring), Distributed tracing, Dependency mapping; (6) Workbooks: aangepaste dashboards, Compliance views, beveiligingspositie.
Vereisten
- Azure subscription
- Log Analytics workspace strategy (how many? where?)
- Retention requirements (compliance-driven)
- Alert recipients defined
- Budget (data ingestion costs β¬2-5/GB)
- Query expertise (KQL)
Implementatie
Maak aan loggen Analytics workspace(s), Schakel in diagnostic settings op alle resources, Configureer alerts (critical: VM down, opslag capacity, security gebeurtenissen), Maak aan action groups, implementeren workbooks.
Compliance en Auditing
Azure monitoren voldoet aan: BIO 12.04.01 (Logging en monitoring mandatory), ISO 27001 A.12.4.1 (Gebeurtenissen logging en audittrails), NIS2 Artikel 21 (Security monitoring capabilities).
Monitoring
Gebruik PowerShell-script azure-monitor.ps1 (functie Invoke-Monitoring) β Controleren.
Remediatie
Gebruik PowerShell-script azure-monitor.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
- BIO: 12.04.01 - Logging en monitoring
- ISO 27001:2022: A.12.4.1 - Gebeurtenissen logging en audittrails
- NIS2: Artikel - Security monitoring
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).
Risico zonder implementatie
Management Samenvatting
Azure Monitor Architecture: Log Analytics Workspace (central log repository - 365-730 dagen retention), Diagnostic settings ALL resources (Activity + Resource logs), Alert rules (security + operational events), Action Groups (notification routing), Workbooks (dashboards), Application Insights (APM). Prerequisite Microsoft Sentinel. Kosten: β¬2-5/GB ingestion (β¬500-2000/maand typical). Activatie: Deploy LAW β Enable diagnostic settings β Configure alerts. Verplicht BIO 12.04, ISO 27001 A.12.4. Implementatie: 24-40 uur. FOUNDATION observability + security - prerequisite Sentinel SIEM.
- Implementatietijd: 40 uur
- FTE required: 0.2 FTE