Skip to main content

CCC.Logging.C07: Detect and Alert on Log Service Tampering

Control ID:CCC.Logging.C07
Title:Detect and Alert on Log Service Tampering
Objective:Alert when any component of the critical logging infrastructure is disabled, modified, or deleted, indicating a defense evasion attempt.
Control Family:
Logging and Monitoring

Related Threats

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.Core.TH16Publications are DisabledPublication of events, metrics, and runtime logs may be disabled, leading to a lack of expected security and operational information being shared. This can impact system availability by delaying the detection of incidents while also impacting system design decisions and enforcement of operational thresholds, such as autoscaling or cost management.
1
1
0

Related Capabilities

IDTitleDescription
CCC.Core.F10Log PublicationThe service automatically publishes structured, verbose records of activities, operations, or events that occur within the service.

Guideline Mappings

Reference IDEntry IDStrengthRemarks
NIST-CSF
DE.CM-03
0
-
NIST-CSF
DE.CM-09
0
-
NIST_800_53
SI-4
0
-
NIST_800_53
CA-7
0
-
NIST_800_53
AU-6
0
-

Assessment Requirements

IDDescriptionApplicability
CCC.Logging.C07.TR01When an audit log event is recorded that corresponds to a modification of the logging service configuration such as disabling a log trail, deleting a log sink, or altering a log forwarding rule, an alert MUST be generated.
tlp-clear
tlp-green
tlp-amber
tlp-red