unified
UC-LOG-03 — Protect audit logs and retain them for required periods
Protect audit information and logging tools from unauthorized access, modification, and deletion: restrict access to a need-to-know subset of personnel, forward records to storage that users of the source system cannot alter, and alert on tampering attempts. Allocate log storage capacity consistent with retention requirements, and alert designated personnel and take defined actions when logging fails or capacity thresholds are reached. Retain audit records per a documented schedule that satisfies the longest applicable legal and regulatory period — for example five years where transaction-reconstruction rules apply — with recent security logs readily available for analysis.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Logging, Monitoring & Detection
- type
- preventive
- category
- technical
Details
- unified_id
- UC-LOG-03
- title
- Protect audit logs and retain them for required periods
- statement
- Protect audit information and logging tools from unauthorized access, modification, and deletion: restrict access to a need-to-know subset of personnel, forward records to storage that users of the source system cannot alter, and alert on tampering attempts. Allocate log storage capacity consistent with retention requirements, and alert designated personnel and take defined actions when logging fails or capacity thresholds are reached. Retain audit records per a documented schedule that satisfies the longest applicable legal and regulatory period — for example five years where transaction-reconstruction rules apply — with recent security logs readily available for analysis.
- domain
- Logging, Monitoring & Detection
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- AU-4
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AU-5
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AU-9
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AU-11
- coverage
- full
- relationship
- superset_of
- framework
- nydfs-500
- control_id
- 500.6
- coverage
- partial
- delta
- also requires trails reconstructing material financial transactions
- relationship
- intersects_with
- guidance
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-05
- propositionTitle
- Verifiable agent action logs and authorization traceability
- sourcePages
- Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency
Source
No record-specific source URL is provided.
Connections
- UC-LOG-03 — Protect audit logs and retain them for required periods mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Protecting logs from modification/deletion and alerting on tampering preserves audit-trail integrity so privileged users cannot cover tracks or repudiate.
- UC-LOG-03 — Protect audit logs and retain them for required periods mitigates Missing or insufficient logging and audit trails
- strength
- primary
- rationale
- Tamper-resistant forwarding, tamper alerts, and retention prevent records being deleted/altered or aging out, so trails are not lost.
- UC-LOG-03 — Protect audit logs and retain them for required periods mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Protecting and retaining logs preserves the forensic evidence attackers would erase after locating and stealing data.
- UC-LOG-03 — Protect audit logs and retain them for required periods maps_to AU-11 — Audit Record Retention
- framework
- nist-800-53
- control_id
- AU-11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-LOG-03 — Protect audit logs and retain them for required periods
- Audit Logging Coverage & Integrity Operations operates UC-LOG-03 — Protect audit logs and retain them for required periods
- UC-LOG-03 — Protect audit logs and retain them for required periods maps_to 500.6 — Audit trail
- framework
- nydfs-500
- control_id
- 500.6
- coverage
- partial
- delta
- also requires trails reconstructing material financial transactions
- relationship
- intersects_with
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-03 — Protect audit logs and retain them for required periods maps_to AU-5 — Response to Audit Logging Process Failures
- framework
- nist-800-53
- control_id
- AU-5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Cybersecurity Assurance Review tests UC-LOG-03 — Protect audit logs and retain them for required periods
- UC-LOG-03 — Protect audit logs and retain them for required periods maps_to AU-9 — Protection of Audit Information
- framework
- nist-800-53
- control_id
- AU-9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-03 — Protect audit logs and retain them for required periods informed_by NIST-AGI-05 — Verifiable agent action logs and authorization traceability
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-05
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency
- UC-LOG-03 — Protect audit logs and retain them for required periods maps_to AU-4 — Audit Log Storage Capacity
- framework
- nist-800-53
- control_id
- AU-4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-03 — Protect audit logs and retain them for required periods mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Immutable log storage and tamper alerts counter the anti-forensic log-deletion tactic APT campaigns use to hide persistence.