You periodically check that you're logging the right events.
What it actually means
What's worth logging changes as your environment does. Periodically review the set of events you capture and adjust it — so you're not missing new systems or drowning in noise.
Pass or fail — an assessor needs a "yes" to each
- The logged-event set is reviewed on a defined cadence.
- Updates are made as systems/threats change.
What to have ready
- Review records / change history for logging config
- Policy defining the review cadence
Where teams trip up
- Logging configured once and never revisited
- New systems added without logging
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Audit & Accountability (3.3)
3.3.1 — Create and retain audit logs3.3.2 — Trace actions to individual users3.3.4 — Alert when logging breaks3.3.5 — Correlate and review your logs3.3.6 — Reduce logs and generate reports3.3.7 — Synchronize clocks for time stamps3.3.8 — Protect your logs from tampering3.3.9 — Limit who manages logging