unified

UC-LOG-02 — Record complete audit content with synchronized clocks

Capture audit records whose content establishes what happened, when it happened, where it occurred, the source, the outcome, and the identity of associated users or subjects, with centrally managed additional fields where investigations require them. Synchronize clocks on all logging systems to an approved authoritative time source, record timestamps in a consistent format mappable to UTC with defined granularity, and monitor for and correct clock drift.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Logging, Monitoring & Detection
type
detective
category
technical

Details

unified_id
UC-LOG-02
title
Record complete audit content with synchronized clocks
statement
Capture audit records whose content establishes what happened, when it happened, where it occurred, the source, the outcome, and the identity of associated users or subjects, with centrally managed additional fields where investigations require them. Synchronize clocks on all logging systems to an approved authoritative time source, record timestamps in a consistent format mappable to UTC with defined granularity, and monitor for and correct clock drift.
domain
Logging, Monitoring & Detection
control_type
detective
control_category
technical
members
  • framework
    nist-800-53
    control_id
    AU-3
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    AU-8
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.17
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections