unified

UC-LOG-03 — Protect audit logs and retain them for required periods

Protect audit information and logging tools from unauthorized access, modification, and deletion: restrict access to a need-to-know subset of personnel, forward records to storage that users of the source system cannot alter, and alert on tampering attempts. Allocate log storage capacity consistent with retention requirements, and alert designated personnel and take defined actions when logging fails or capacity thresholds are reached. Retain audit records per a documented schedule that satisfies the longest applicable legal and regulatory period — for example five years where transaction-reconstruction rules apply — with recent security logs readily available for analysis.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Logging, Monitoring & Detection
type
preventive
category
technical

Details

unified_id
UC-LOG-03
title
Protect audit logs and retain them for required periods
statement
Protect audit information and logging tools from unauthorized access, modification, and deletion: restrict access to a need-to-know subset of personnel, forward records to storage that users of the source system cannot alter, and alert on tampering attempts. Allocate log storage capacity consistent with retention requirements, and alert designated personnel and take defined actions when logging fails or capacity thresholds are reached. Retain audit records per a documented schedule that satisfies the longest applicable legal and regulatory period — for example five years where transaction-reconstruction rules apply — with recent security logs readily available for analysis.
domain
Logging, Monitoring & Detection
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    AU-4
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    AU-5
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    AU-9
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    AU-11
    coverage
    full
    relationship
    superset_of
  • framework
    nydfs-500
    control_id
    500.6
    coverage
    partial
    delta
    also requires trails reconstructing material financial transactions
    relationship
    intersects_with
guidance
  • source
    nist-ai-agent-identity
    sourceTitle
    NIST NCCoE: Software and AI Agent Identity and Authorization
    propositionId
    NIST-AGI-05
    propositionTitle
    Verifiable agent action logs and authorization traceability
    sourcePages
    Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency

Source

No record-specific source URL is provided.

Connections