What are some of the best practice for auditing confluence access?
Apart from using the usual ITGC framework; looking at user access provisioning, termination, access review what are things do people look out for?
Also given the immense amount of logs, what are some of the key logs that should be reviewed?