Audit data and tools are protected from unauthorized access or change.
What it actually means
An attacker's first move is often to erase the logs. Audit records and the logging tools themselves must be protected from unauthorized access, modification, and deletion — typically by shipping logs off the source system to a write-protected central repository.
Pass or fail — an assessor needs a "yes" to each
- Logs are stored where the people generating them can't alter/delete them (central, restricted).
- Access to logging tools/config is restricted.
- Tamper protection / integrity is in place.
What to have ready
- Central log repository with restricted access
- Permissions showing users can't delete their own logs
Where teams trip up
- Logs only on the local machine that made them
- Admins able to wipe the logs of their own activity
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Audit & Accountability (3.3)
3.3.1 — Create and retain audit logs3.3.2 — Trace actions to individual users3.3.3 — Review and update what you log3.3.4 — Alert when logging breaks3.3.5 — Correlate and review your logs3.3.6 — Reduce logs and generate reports3.3.7 — Synchronize clocks for time stamps3.3.9 — Limit who manages logging