Data Governance
Monitoring data often contains sensitive operational information and may be subject to regulatory or contractual requirements. Data governance ensures Unified Monitoring is operated in a compliant and auditable way.
Use this guide to review the controls needed to protect sensitive telemetry and support compliance, accountability, and change management.
Access Control
- Use RBAC to restrict who can view and manage monitoring data. See RBAC.
- Limit access to particularly sensitive metrics or events (for example, those involving customer data or regulated environments).
- Ensure access is logged and regularly reviewed.
Retention and Compliance
- Set retention policies that meet regulatory requirements (for example, keeping certain metrics or events for multiple years).
- Coordinate retention decisions with legal, compliance, and security functions.
- Document which datasets are covered by which policies.
See Retention & Rollups and Limits & Quotas for conceptual guidance.
Data Classification and Tagging
- Use CMDB attributes such as
data_classificationandcriticalityto indicate how monitoring data should be treated. - Ensure that highly sensitive systems are clearly labeled so you can apply stricter controls to their telemetry.
Audit and Change Management
- Ensure that changes to monitoring configuration (policies, routes, integrations) are tracked, reviewed, and tied to change records where appropriate.
- Include monitoring data and configuration in periodic audits.