Skip to main content

Management / Logging / Threats / DEV

Insufficient Logging

CCC.Logging.TH07

If security-critical actions are not logged, it becomes more difficult to detect threats and conduct post-incident analysis.

Related Capabilities

IDTitleDescription
CCC.Core.CP10Log PublicationThe service automatically publishes structured, verbose records of activities, operations, or events that occur within the service.
CCC.Logging.CP01Service Log CaptureAbility to capture logs from all relevant cloud services at varying levels of verbosity.
CCC.Logging.CP02Application Log IngestionSupport for ingesting logs from custom applications deployed within the cloud environment.

Related Controls

IDTitleDescription
CCC.Logging.CN01Centralized and Comprehensive Log AggregationEnsure all operational and security logs from across the cloud environment, including applications, operating systems, network traffic, and cloud service activity, are captured automatically and streamed to a central, secure log management service.

External Mappings

FrameworkIDRemarks
OWASPTOP10A09:2021
CWECWE-223
CWECWE-778