Skip to main content

Management / Logging / Controls / DEV

Centralized and Comprehensive Log Aggregation

CCC.Logging.CN01 · Observability

Ensure all operational and security logs from across the cloud environment, including applications, operating systems, network traffic, and cloud service activity, are captured automatically and streamed to a central, secure log management service.

Related Capabilities

IDTitleDescription
CCC.Core.CP10Log PublicationThe service automatically publishes structured, verbose records of activities, operations, or events that occur within the service.
CCC.Logging.CP01Service Log CaptureAbility to capture logs from all relevant cloud services at varying levels of verbosity.
CCC.Logging.CP02Application Log IngestionSupport for ingesting logs from custom applications deployed within the cloud environment.

Related Threats

IDTitleDescription
CCC.Logging.TH07Insufficient LoggingIf security-critical actions are not logged, it becomes more difficult to detect threats and conduct post-incident analysis.

Assessment Requirements

IDTextApplicability
CCC.Logging.CN01.AR01When a new cloud account is created, provider-level audit and network flow logging MUST be enabled by default and directed to the central sink.tlp-clear, tlp-green, tlp-amber, tlp-red
CCC.Logging.CN01.AR02When a new cloud compute resource is deployed, it MUST be configured to forward all relevant logs (e.g., OS, application, service logs) to the central log sink.tlp-clear, tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.PS-04
NIST_800_53AU-2
NIST_800_53AU-3