Discussion
- AuthorPosts
- 3rd September 2026 at 3:38 am #3507
A vendor says that user and administrator actions are logged. What details should a buyer verify so the logs actually support oversight and investigations?
3rd September 2026 at 5:30 am #3508Accepted answerDefine the events that matter, such as sign-ins, failed access, privilege changes, configuration changes, sensitive data access, exports, and administrative actions. Require each record to identify the actor, time, target, action, and result, using synchronized timestamps. Verify search and export, retention, storage capacity, alerts for logging failures, protection from alteration or deletion, and separation of log administration privileges. Test sample records during evaluation. NIST SP 800-53 Rev. 5 provides the Audit and Accountability control family for event logging, record content, review, protection, retention, and generation.
- AuthorPosts
- You must be logged in to reply to this topic.