Skip to main content

Management / Logging / Controls / DEV

Detect and Alert on Potential Log Exfiltration

CCC.Logging.CN06 · Observability

Identify and alert on anomalous data access patterns that may indicate an attempt to exfiltrate log data.

Related Capabilities

IDTitleDescription
CCC.Core.CP06Access ControlThe service automatically enforces user configurations to restrict or allow access to a specific component or a child resource based on factors such as user identities, roles, groups, or attributes.
CCC.Core.CP14API AccessThe service exposes a port enabling external actors to interact programmatically with the service and its resources using HTTP protocol methods such as GET, POST, PUT, and DELETE.
CCC.Core.CP22Location Lock-InThe service may be configured to restrict the deployment of child resources to specific geographic locations.

Related Threats

IDTitleDescription
CCC.Logging.TH02Unauthorized Data Transfer Out of a Trusted BoundarySensitive log data, including PII, financial transaction details, or system vulnerabilities, is exfiltrated directly from the logging service's query or API interfaces by authorized but malicious insiders or compromised accounts exploiting legitimate access.

Assessment Requirements

IDTextApplicability
CCC.Logging.CN06.AR01When a single principal executes an anomalously high number of log queries, an alert MUST be generated.tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFDE.CM-03
NIST-CSFDE.CM-09
NIST_800_53SI-4
NIST_800_53CA-7
NIST_800_53AU-6