10.3.1 Read access to logs restricted
Read access to audit log files is limited to those with a job-related need.
5
artefacts
3
held by a system
1
at each review
easy
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- SIEM RBAC configuration · SIEM / log platform
- List of users with log read access and justification · SIEM / log platform
- Audit log of log access permissions changes · Identity provider / directory
periodic reviewEvidence produced at each review
- Quarterly access review evidence · Identity provider / directory
governing documentDocuments that govern the control
- Procedure for granting log access · Policy repository / GRC workspace
First move
Automate the pull from your SIEM / log platform. Retention and alert rules exported from the SIEM; review evidence is the closed-alert record with reviewer and time.
Common gaps auditors find
- Wide read access granted
- No review
- Justification missing
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet10.2.2 Audit log content · 10.3.2 Logs protected from modification