Earlier quoted context omitted.
Essentially, it’s straddling two extremes: 1) employees are trusted with secrets, so we have to audit that employees are treating those secrets securely (via tracking, monitoring, etc) 2) we don’t allow employees to have access to secrets whatsoever, therefore we don’t need any auditing or monitoring
Exporting to a SIEM does not correlate to either of those extremes. It’s stupidity and makes auditing worse
Factually, it is necessary for auditing and absolutely correlates with the extreme of needing to monitor the “usage” of “secrets”.
In a highly auditable/“secure” environment, you can’t give secrets to employees with no tracking of when the secrets are used.