{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Logging, Monitoring & Detection","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-03","description":"Protect audit information and logging tools from unauthorized access, modification, and deletion: restrict access to a need-to-know subset of personnel, forward records to storage that users of the source system cannot alter, and alert on tampering attempts. Allocate log storage capacity consistent with retention requirements, and alert designated personnel and take defined actions when logging fails or capacity thresholds are reached. Retain audit records per a documented schedule that satisfies the longest applicable legal and regulatory period — for example five years where transaction-reconstruction rules apply — with recent security logs readily available for analysis.","details":{"control_category":"technical","control_type":"preventive","domain":"Logging, Monitoring & Detection","guidance":[{"propositionId":"NIST-AGI-05","propositionTitle":"Verifiable agent action logs and authorization traceability","source":"nist-ai-agent-identity","sourcePages":"Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"}],"members":[{"control_id":"AU-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AU-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AU-9","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AU-11","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"500.6","coverage":"partial","delta":"also requires trails reconstructing material financial transactions","framework":"nydfs-500","relationship":"intersects_with"}],"statement":"Protect audit information and logging tools from unauthorized access, modification, and deletion: restrict access to a need-to-know subset of personnel, forward records to storage that users of the source system cannot alter, and alert on tampering attempts. Allocate log storage capacity consistent with retention requirements, and alert designated personnel and take defined actions when logging fails or capacity thresholds are reached. Retain audit records per a documented schedule that satisfies the longest applicable legal and regulatory period — for example five years where transaction-reconstruction rules apply — with recent security logs readily available for analysis.","title":"Protect audit logs and retain them for required periods","unified_id":"UC-LOG-03"},"id":"uc:UC-LOG-03","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-03","sourceIds":["nist-800-53","nist-ai-agent-identity","nydfs-500"],"sourceUrl":null,"title":"UC-LOG-03 — Protect audit logs and retain them for required periods","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:058988fa1e861dd7032642d84c30504d7c51bb1c8b4efc6a5cc1493d67ff285f","properties":{"rationale":"Protecting logs from modification/deletion and alerting on tampering preserves audit-trail integrity so privileged users cannot cover tracks or repudiate.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","sourceId":"uc:UC-LOG-03","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:09eece294f443acd1ed951438aa338eddc1c625914950cb927fead63e22bc86c","properties":{"rationale":"Tamper-resistant forwarding, tamper alerts, and retention prevent records being deleted/altered or aging out, so trails are not lost.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","sourceId":"uc:UC-LOG-03","targetDetailPath":"/data/v1/records/risk-log-missing-audit-trail-37d1ba80.json","targetId":"risk:log-missing-audit-trail","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1993a983f2a09427091e49375da5e2f760da75d2de3cfbb7f2308f246ceafba4","properties":{"rationale":"Protecting and retaining logs preserves the forensic evidence attackers would erase after locating and stealing data.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","sourceId":"uc:UC-LOG-03","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:220a53bf67201807df74f5d664c0d1dc0bc21bcef4c022a827e7dbcc45f4f963","properties":{"control_id":"AU-11","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","sourceId":"uc:UC-LOG-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-au-11-bcd6162b.json","targetId":"ctrl:nist-800-53:AU-11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:49be9acbcd18ced6d73b030b0e65740ee02e112df785f172d53155e620571dbd","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","targetId":"uc:UC-LOG-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4d39aba6d5c1acc8a05c02a45649495379fa01912dd0c4218b99a86fb607e491","properties":{},"sourceDetailPath":"/data/v1/records/wf-c52-fa969595.json","sourceId":"wf:C52","targetDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","targetId":"uc:UC-LOG-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4eee70c373d257b88d04508560fa2d493236a925b3926a17b21d680720504410","properties":{"control_id":"500.6","coverage":"partial","delta":"also requires trails reconstructing material financial transactions","framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","sourceId":"uc:UC-LOG-03","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-6-c10e1c50.json","targetId":"ctrl:nydfs-500:500.6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6293e6afb7ff806408b0d50c53a45ad6530dee904a5ce4a61bff158e6e30305e","properties":{"control_id":"AU-5","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","sourceId":"uc:UC-LOG-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-au-5-acb1154c.json","targetId":"ctrl:nist-800-53:AU-5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b4486a90fcc13709963f058683c39a2d32b25fff3c3fe9ad3aa0472fdb33c500","properties":{},"sourceDetailPath":"/data/v1/records/wf-a1-f09c8201.json","sourceId":"wf:A1","targetDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","targetId":"uc:UC-LOG-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bbb39a7d2a6913f6cd854dc2e9cc1abbc0d1321abd6e466323796c57d270979d","properties":{"control_id":"AU-9","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","sourceId":"uc:UC-LOG-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-au-9-d44c41a3.json","targetId":"ctrl:nist-800-53:AU-9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bbc2da623855fd927844f33bc1f7309b32766a5f7370c3d37893f69d51483644","properties":{"control_id":"NIST-AGI-05","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","sourceId":"uc:UC-LOG-03","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-05-1adf3e6a.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-05","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cc2ea8d90c4cefb105295f315041d6046c3ad519493e36ba2b2cc50bb56c4fac","properties":{"control_id":"AU-4","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","sourceId":"uc:UC-LOG-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-au-4-1d04f08b.json","targetId":"ctrl:nist-800-53:AU-4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e831b8a5d7d217ed1bfa299b37207847c718595e688084ec797d5acf0f2bca14","properties":{"rationale":"Immutable log storage and tamper alerts counter the anti-forensic log-deletion tactic APT campaigns use to hide persistence.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","sourceId":"uc:UC-LOG-03","targetDetailPath":"/data/v1/records/risk-cyber-coordinated-campaign-b5879769.json","targetId":"risk:cyber-coordinated-campaign","type":"mitigates"}],"schemaVersion":1}
