Hi,
I think that the most important is monitoring sensitive data.
First, you should create your own sensitive data dictionary and add it to the Global Objects. After that run a Sensitive data scan and review the results - accept or decline.
Then you have the first audit policy -> all events on sensitive data.
What's else? It depends on your corps. Try to find audit guidelines for monitoring DB/systems, maybe you have guidelines in local law....
If you do not know what you should monitor you can always use the match criteria -> All Events -> login/logout/query..... but I know that is no solution.... it is only a huge problem...
------------------------------
Karol Gruszczyński
IT Security Expert
Trafford IT
Warsaw
------------------------------