Skip to main content

Management / Logging

Controls

Version:
IDTitleObjective
CCC.Logging.CN01Centralized and Comprehensive Log AggregationEnsure all operational and security logs from across the cloud environment, including applications, operating systems, network traffic, and cloud service activity, are captured automatically and streamed to a central, secure log management service.
CCC.Logging.CN02Enforce Data Retention Policy for LogsEnsure that the retention period configured for logs aligns with the organization's data retention policy.
CCC.Logging.CN03Enable Object Lock On Log BucketEnsure log immutability by enabling Write Once, Read Many (WORM) protection using object lock on log storage buckets. This prevents logs from being modified or deleted during the defined retention period, supporting compliance and forensic integrity.
CCC.Logging.CN04Restrict Field And Log Type AccessConfigure access to logs to follow the principle of least privilege in particular where technically possible limit the log fields users have access to to prevent accidental exposure to sensitive information such as PII.
CCC.Logging.CN05Ensure Log Bucket is Not Publicly AccessibleEnsure that log storage buckets are not publicly accessible to prevent unauthorized access to sensitive log data. In addition, logs should be replicated to another cloud region to enhance availability, durability, and support disaster recovery requirements.
CCC.Logging.CN06Detect and Alert on Potential Log ExfiltrationIdentify and alert on anomalous data access patterns that may indicate an attempt to exfiltrate log data.
CCC.Logging.CN07Detect and Alert on Log Service TamperingAlert when any component of the critical logging infrastructure is disabled, modified, or deleted, indicating a defense evasion attempt.