unified
UC-LOG-01 — Log security-relevant events across all systems
Enable audit logging on all systems, applications, and network components, generating records for a defined catalog of security-relevant event types — at minimum authentication, all access to sensitive or regulated data (such as cardholder data), privileged actions, account and configuration changes, and security-tool events. Review and update the event catalog periodically with system owners, ensure logging is enabled by default on newly deployed components, and verify logging coverage on a defined cadence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Logging, Monitoring & Detection
- type
- detective
- category
- technical
Details
- unified_id
- UC-LOG-01
- title
- Log security-relevant events across all systems
- statement
- Enable audit logging on all systems, applications, and network components, generating records for a defined catalog of security-relevant event types — at minimum authentication, all access to sensitive or regulated data (such as cardholder data), privileged actions, account and configuration changes, and security-tool events. Review and update the event catalog periodically with system owners, ensure logging is enabled by default on newly deployed components, and verify logging coverage on a defined cadence.
- domain
- Logging, Monitoring & Detection
- control_type
- detective
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- AU-2
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AU-12
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.15
- coverage
- partial
- delta
- also requires protecting, storing, and analysing produced logs
- relationship
- intersects_with
- framework
- pci-dss
- control_id
- PCI-Req10
- coverage
- partial
- delta
- also requires daily review, 12-month retention, time synchronization, log protection
- relationship
- intersects_with
- framework
- hipaa
- control_id
- HIPAA-164.312(b)
- coverage
- full
- relationship
- superset_of
- guidance
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-05
- propositionTitle
- Verifiable agent action logs and authorization traceability
- sourcePages
- Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency
Source
No record-specific source URL is provided.
Connections
- Cybersecurity Assurance Review tests UC-LOG-01 — Log security-relevant events across all systems
- Security Control Assessment & POA&M Remediation tests UC-LOG-01 — Log security-relevant events across all systems
- UC-LOG-01 — Log security-relevant events across all systems maps_to PCI-Req10 — Log and monitor all access to system components and cardholder data
- framework
- pci-dss
- control_id
- PCI-Req10
- coverage
- partial
- delta
- also requires daily review, 12-month retention, time synchronization, log protection
- relationship
- intersects_with
- source_version
- v4.0.1
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-LOG-01 — Log security-relevant events across all systems
- UC-LOG-01 — Log security-relevant events across all systems mitigates Missing or insufficient logging and audit trails
- strength
- primary
- rationale
- Enabling audit logging across all systems for a defined security-event catalog directly eliminates absent/insufficient audit trails.
- UC-LOG-01 — Log security-relevant events across all systems informed_by NIST-AGI-05 — Verifiable agent action logs and authorization traceability
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-05
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency
- UC-LOG-01 — Log security-relevant events across all systems maps_to A.8.15 — Logging
- framework
- iso-27001
- control_id
- A.8.15
- coverage
- partial
- delta
- also requires protecting, storing, and analysing produced logs
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-01 — Log security-relevant events across all systems mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Logging authentication and privileged actions creates the accountability record that detects rights abuse and defeats repudiation of actions.
- UC-LOG-01 — Log security-relevant events across all systems maps_to AU-12 — Audit Record Generation
- framework
- nist-800-53
- control_id
- AU-12
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-01 — Log security-relevant events across all systems maps_to HIPAA-164.312(b) — Audit controls recording activity in systems with ePHI
- framework
- hipaa
- control_id
- HIPAA-164.312(b)
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 45 CFR Parts 160/164 (Security, Privacy, Breach Notification)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-01 — Log security-relevant events across all systems maps_to AU-2 — Event Logging
- framework
- nist-800-53
- control_id
- AU-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Audit Logging Coverage & Integrity Operations operates UC-LOG-01 — Log security-relevant events across all systems
- UC-LOG-01 — Log security-relevant events across all systems mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Logging access to sensitive/regulated (e.g., cardholder) data provides a targeted detection input for locating and investigating exfiltration.
- SOC 2 Type II Interim Testing tests UC-LOG-01 — Log security-relevant events across all systems
- UC-LOG-01 — Log security-relevant events across all systems mitigates No security monitoring or supervision of privileged activity
- strength
- related
- rationale
- Logging privileged actions is the prerequisite record that makes supervision of privileged activity possible.