unified
UC-LOG-02 — Record complete audit content with synchronized clocks
Capture audit records whose content establishes what happened, when it happened, where it occurred, the source, the outcome, and the identity of associated users or subjects, with centrally managed additional fields where investigations require them. Synchronize clocks on all logging systems to an approved authoritative time source, record timestamps in a consistent format mappable to UTC with defined granularity, and monitor for and correct clock drift.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Logging, Monitoring & Detection
- type
- detective
- category
- technical
Details
- unified_id
- UC-LOG-02
- title
- Record complete audit content with synchronized clocks
- statement
- Capture audit records whose content establishes what happened, when it happened, where it occurred, the source, the outcome, and the identity of associated users or subjects, with centrally managed additional fields where investigations require them. Synchronize clocks on all logging systems to an approved authoritative time source, record timestamps in a consistent format mappable to UTC with defined granularity, and monitor for and correct clock drift.
- domain
- Logging, Monitoring & Detection
- control_type
- detective
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- AU-3
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AU-8
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.17
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-LOG-02 — Record complete audit content with synchronized clocks
- UC-LOG-02 — Record complete audit content with synchronized clocks maps_to AU-3 — Content of Audit Records
- framework
- nist-800-53
- control_id
- AU-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-LOG-02 — Record complete audit content with synchronized clocks
- UC-LOG-02 — Record complete audit content with synchronized clocks mitigates Missing or insufficient logging and audit trails
- strength
- primary
- rationale
- Capturing complete audit content directly remedies insufficient records that cannot establish what happened, when, where, and by whom.
- Audit Logging Coverage & Integrity Operations operates UC-LOG-02 — Record complete audit content with synchronized clocks
- UC-LOG-02 — Record complete audit content with synchronized clocks maps_to AU-8 — Time Stamps
- framework
- nist-800-53
- control_id
- AU-8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-02 — Record complete audit content with synchronized clocks mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Recording identity, source, and outcome with clocks synced to an authoritative source delivers reliable attribution that defeats repudiation.
- UC-LOG-02 — Record complete audit content with synchronized clocks maps_to A.8.17 — Clock synchronization
- framework
- iso-27001
- control_id
- A.8.17
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-02 — Record complete audit content with synchronized clocks mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Complete, accurately time-synced records enable reliable reconstruction of an exfiltration timeline during investigation.