Skip to main content

Management / Auditlog

Controls

Version:
IDTitleObjective
CCC.AuditLog.CN01Implement Digital Signatures With Hash ChainingDigital signatures allows for external verification of log data tampering and hash chaining allows for deleted log files to be detected.
CCC.AuditLog.CN02Enable And Validate All Audit Log TypesReview audit log configuration and ensure that all audit log types are being generated and replicated to configured sinks
CCC.AuditLog.CN03Alert On Audit Log Changes And AccessEnsure that specific alerts have been configured to detect changes in audit log configuration such as disabling exporting of logs. Alerts MUST also be created to detect changes in retention/object lock policies for exported data log sources/buckets.
CCC.AuditLog.CN04Ensure Access Logging Is Enabled on the Audit Log BucketEnsure that access logging is enabled for the audit log storage bucket to capture all requests made to the bucket, providing an audit trail of data access.
CCC.AuditLog.CN05Export Audit Logs To BucketConfigure audit logs to be sent to a external bucket where they can be globally replicated and can be subject to greater access control and data retention polices.
CCC.AuditLog.CN06Enforce Retention Policy on Audit Log BucketConfigure a custom retention policy on the designated audit log bucket to ensure that logs are retained for the correct number of days as defined by your organization's policy.
CCC.AuditLog.CN07Enforce MFA Delete on Audit Log BucketEnable Multi-Factor Authentication (MFA) delete on the audit log bucket to provide greater protection against accidental or malicious deletion of audit data.
CCC.AuditLog.CN08Enable Object Lock On Audit Log BucketEnsure that object log is enabled globally on all objects with the bucket. The lock time MUST be configured to meet your organization, legal and compliance goals. Deletion attempts before the lock period MUST be denied.
CCC.AuditLog.CN09Restrict Field And Log Type AccessConfigure access to audit logs to follow the principle of least privilege in particular where technically possible limit the log fields users have access to to prevent accidental exposure to sensitive information such as PII.
CCC.AuditLog.CN10Ensure Audit Bucket is Not Publicly AccessibleEnsure that audit log storage buckets are not publicly accessible to prevent unauthorized exposure of sensitive log data.