Skip to main content

Management / Auditlog / Controls / DEV

Enable And Validate All Audit Log Types

CCC.AuditLog.CN02 · Observability

Review audit log configuration and ensure that all audit log types are being generated and replicated to configured sinks

Related Capabilities

IDTitleDescription
CCC.Core.CP11BackupThe service can generate copies of its data or configurations in the form of automated backups, snapshot-based backups, or incremental backups.
CCC.Core.CP18Resource VersioningThe service automatically assigns versions to child resources which can be used to preserve, retrieve, and restore past iterations.

Related Threats

IDTitleDescription
CCC.Core.TH06Data is Lost or CorruptedServices that rely on accurate data are susceptible to disruption in the event of data loss or corruption. Any actions that lead to the unintended deletion, alteration, or limited access to data can impact the availability of the service and the system it is part of.

Assessment Requirements

IDTextApplicability
CCC.AuditLog.CN02.AR01When a manual action is performed to generate each audit log type, then the corresponding audit log type MUST be generated and recorded.tlp-red, tlp-amber

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.PS-04
NIST_800_53AU-2
NIST_800_53AU-3
NIST_800_53AU-12