Skip to main content

Management / Auditlog / Threats / DEV

Insufficient Audit Logs

CCC.AUDITLOG.TH01

If security critical audit events are not logged then it increases the difficulty to detect threats and perform post incident analysis.

Related Capabilities

IDTitleDescription
CCC.Core.CP03Access Log PublicationThe service automatically publishes structured, verbose records of activities performed within the scope of the service by external actors.
CCC.Core.CP10Log PublicationThe service automatically publishes structured, verbose records of activities, operations, or events that occur within the service.

External Mappings

FrameworkIDRemarks
OWASPTOP10A09:2021
CWECWE-778
CWECWE-223