What should buyers require from software audit logs?

Discussion

Open questionLast verified: 2026-08-15
  • Author
    Posts
  • #3507

    A vendor says that user and administrator actions are logged. What details should a buyer verify so the logs actually support oversight and investigations?

    #3508
    Accepted answer

    Define the events that matter, such as sign-ins, failed access, privilege changes, configuration changes, sensitive data access, exports, and administrative actions. Require each record to identify the actor, time, target, action, and result, using synchronized timestamps. Verify search and export, retention, storage capacity, alerts for logging failures, protection from alteration or deletion, and separation of log administration privileges. Test sample records during evaluation. NIST SP 800-53 Rev. 5 provides the Audit and Accountability control family for event logging, record content, review, protection, retention, and generation.

  • You must be logged in to reply to this topic.

Reply to this discussion

You must be logged in to reply. Editors verify buy-side questions and cite reviews when answering.

Create an account