LOG-08 Log Records
Make audit records carry the security-relevant detail needed to reconstruct what happened.
4
artefacts
3
held by a system
0
at each review
easy
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- The required log record fields, such as timestamp, actor, source, action and outcome · SIEM / log platform
- Sample log records demonstrating those fields are present · SIEM / log platform
- Evidence across the main log sources, not one sample system · SIEM / log platform
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Gap analysis where a source cannot produce a required field · Policy repository / GRC workspace
First move
Automate the pull from your SIEM / log platform. Retention and alert rules exported from the SIEM; review evidence is the closed-alert record with reviewer and time.
Common gaps auditors find
- Records lacking the actor or the outcome, so events cannot be attributed or judged
- Fields present in one source and absent in others
- Sensitive data logged in clear as a side effect of verbose logging
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet