workflow
Audit Logging Coverage & Integrity Operations
Monthly operator cycle that verifies audit-logging coverage against the security-relevant event catalog, validates record content-completeness and clock synchronization, and confirms log protection, alerting, and retention, producing the coverage matrix, record content-completeness results, clock-drift report, and retention and capacity attestation evidence pack each cycle. Each instance attaches to the EXISTING audit-logging Control in the control library (control_id UC-LOG-01; framework nist-800-53 / iso-27001 / pci-dss / nydfs-500; domain logging_monitoring_detection; monthly frequency), with UC-LOG-02 / UC-LOG-03 linked by item relationships — enrich that Control's operating history, never create a duplicate control. Every gap, remediation, and carry-forward is logged as an Issue related back to that Control. In scope: every in-scope system, application, and network component, the security-relevant event catalog, and log protection and retention configuration. Out of scope: SIEM detection-rule tuning and incident investigation — surfaced detection gaps hand off to the SOC / SIEM-operations and incident-response workflows, not this cycle. No upstream workflow feeds this cycle; the prior cycle's open corrective-action and carry-forward Issue items (related to the anchor Control) plus the prior cycle's archived workflow instance are its only inputs, and close-and-archive seeds the next monthly run of itself.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- domains
- controls
- standards
- nist-800-53
- iso-27001
- pci-dss
- nydfs-500
- sourceTemplateId
- workflow-library:controls-audit-logging-coverage-integrity-operations
- releaseId
- sha256:4b7fee34ffe97fe67233456545758640c8491dfcb20c1331eb266b66f96734b4
- canonicalUrl
- https://workflow-library.com/all/?w=controls-audit-logging-coverage-integrity-operations
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-LOG-01
- UC-LOG-02
- UC-LOG-03
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:4b7fee34ffe97fe67233456545758640c8491dfcb20c1331eb266b66f96734b4
Connections
- Audit Logging Coverage & Integrity Operations operates UC-LOG-03 — Protect audit logs and retain them for required periods
- Audit Logging Coverage & Integrity Operations operates UC-LOG-02 — Record complete audit content with synchronized clocks
- Audit Logging Coverage & Integrity Operations operates UC-LOG-01 — Log security-relevant events across all systems