{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Logging, Monitoring & Detection","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-01","description":"Enable audit logging on all systems, applications, and network components, generating records for a defined catalog of security-relevant event types — at minimum authentication, all access to sensitive or regulated data (such as cardholder data), privileged actions, account and configuration changes, and security-tool events. Review and update the event catalog periodically with system owners, ensure logging is enabled by default on newly deployed components, and verify logging coverage on a defined cadence.","details":{"control_category":"technical","control_type":"detective","domain":"Logging, Monitoring & Detection","guidance":[{"propositionId":"NIST-AGI-05","propositionTitle":"Verifiable agent action logs and authorization traceability","source":"nist-ai-agent-identity","sourcePages":"Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"}],"members":[{"control_id":"AU-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AU-12","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.8.15","coverage":"partial","delta":"also requires protecting, storing, and analysing produced logs","framework":"iso-27001","relationship":"intersects_with"},{"control_id":"PCI-Req10","coverage":"partial","delta":"also requires daily review, 12-month retention, time synchronization, log protection","framework":"pci-dss","relationship":"intersects_with"},{"control_id":"HIPAA-164.312(b)","coverage":"full","framework":"hipaa","relationship":"superset_of"}],"statement":"Enable audit logging on all systems, applications, and network components, generating records for a defined catalog of security-relevant event types — at minimum authentication, all access to sensitive or regulated data (such as cardholder data), privileged actions, account and configuration changes, and security-tool events. Review and update the event catalog periodically with system owners, ensure logging is enabled by default on newly deployed components, and verify logging coverage on a defined cadence.","title":"Log security-relevant events across all systems","unified_id":"UC-LOG-01"},"id":"uc:UC-LOG-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-01","sourceIds":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","pci-dss"],"sourceUrl":null,"title":"UC-LOG-01 — Log security-relevant events across all systems","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0cd3e97c2f6b55449f7405198ed81050e893088fc21d7753862324610d954923","properties":{},"sourceDetailPath":"/data/v1/records/wf-a1-f09c8201.json","sourceId":"wf:A1","targetDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","targetId":"uc:UC-LOG-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:112d83b1f9f2bc62970664d444e59d79679ef01683951fd882e3ad43b4717908","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","targetId":"uc:UC-LOG-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:34cbd2a80158a94ce449d2367d9e0b1460197c30e637e3b46447d5bd42550b40","properties":{"control_id":"PCI-Req10","coverage":"partial","delta":"also requires daily review, 12-month retention, time synchronization, log protection","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req10-c587ee2b.json","targetId":"ctrl:pci-dss:PCI-Req10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4408e3b64a0092c8573e16c800acb260c69b277fd0916419296973663802dc8e","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","targetId":"uc:UC-LOG-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:70e5368a60517c7d1a5a902712327d0eeb1490207b7cd6b11878bae290665e84","properties":{"rationale":"Enabling audit logging across all systems for a defined security-event catalog directly eliminates absent/insufficient audit trails.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/risk-log-missing-audit-trail-37d1ba80.json","targetId":"risk:log-missing-audit-trail","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7f0fec625be7c5596d502277287495e3c45f075169b187cfcbbdaf372f5f708b","properties":{"control_id":"NIST-AGI-05","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-05-1adf3e6a.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-05","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a2a316f5916d3671f160c275b17626637917d041fef59df212398e607e152aa4","properties":{"control_id":"A.8.15","coverage":"partial","delta":"also requires protecting, storing, and analysing produced logs","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-15-ab7dd8ce.json","targetId":"ctrl:iso-27001:A.8.15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a7da59065613ede3740dad783a788bcdc502c2f193696c8d8be8b2a3c5f70637","properties":{"rationale":"Logging authentication and privileged actions creates the accountability record that detects rights abuse and defeats repudiation of actions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b94a8686dccf0aafca7a8b4724b4f91591492e26f7179b83a6b4304d29386158","properties":{"control_id":"AU-12","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-au-12-2081054f.json","targetId":"ctrl:nist-800-53:AU-12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bf5f7706b3e73a46db661616cf5be6eac2a75128746032843f715220ed4b0d51","properties":{"control_id":"HIPAA-164.312(b)","coverage":"full","delta":null,"framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-b-7272303c.json","targetId":"ctrl:hipaa:HIPAA-164.312(b)","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d7e4f6ab399acd6339516a6783434a16aa2c6d6eeb4711334fa50a53b32fce02","properties":{"control_id":"AU-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-au-2-52e1ade4.json","targetId":"ctrl:nist-800-53:AU-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d7f433af76c52866d5e295cfe6b0d524560ba7efe642a3ac345a2a95c9485355","properties":{},"sourceDetailPath":"/data/v1/records/wf-c52-fa969595.json","sourceId":"wf:C52","targetDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","targetId":"uc:UC-LOG-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8d42bf85ad8b78bd895f84c62c95e0675bfd71b283e9534f0fc444210b33e94","properties":{"rationale":"Logging access to sensitive/regulated (e.g., cardholder) data provides a targeted detection input for locating and investigating exfiltration.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d9c6dc9ba7248c9b79cf8490e77e5dea56d65b04dcccdbb7dd89a7d673b731a9","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","targetId":"uc:UC-LOG-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e87c480c0bb2933a8509552f48ac75c5ade41b1458f0d7bab2cd9adfe1f5aeb6","properties":{"rationale":"Logging privileged actions is the prerequisite record that makes supervision of privileged activity possible.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/risk-log-no-monitoring-supervision-712fe573.json","targetId":"risk:log-no-monitoring-supervision","type":"mitigates"}],"schemaVersion":1}
