PR.PS-04 Log records are generated and made available for continuous monitoring
Log records are generated and made available for continuous monitoring. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
5
artefacts
3
held by a system
1
at each review
easy
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Centralized log collection architecture · SIEM / log platform
- Log retention configuration evidence · SIEM / log platform
- Log integrity protections and audit findings · SIEM / log platform
periodic reviewEvidence produced at each review
- Periodic logging coverage review · SIEM / log platform
governing documentDocuments that govern the control
- Logging policy by data class and system tier · Policy repository / GRC workspace
First move
Automate the pull from your SIEM / log platform. Retention and alert rules exported from the SIEM; review evidence is the closed-alert record with reviewer and time.
Common gaps auditors find
- Critical systems missing from log feed
- Retention shorter than incident windows
- Log integrity not validated
- Coverage review skipped
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk · PR.PS-05 Installation and execution of unauthorized software are prevented