Only a small set of privileged users can manage audit functions.
What it actually means
The people who could turn logging off or change what's captured should be a small, specific group — separate where possible from the general admins whose actions are being logged. It keeps the audit trail honest.
Pass or fail — an assessor needs a "yes" to each
- Management of audit/logging functions is restricted to a named subset of privileged users.
- That group is documented.
What to have ready
- Role assignments for audit/log management
- Policy naming who may manage logging
Where teams trip up
- Every admin can manage (or disable) logging
- No separation between log managers and the logged
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Audit & Accountability (3.3)
3.3.1 — Create and retain audit logs3.3.2 — Trace actions to individual users3.3.3 — Review and update what you log3.3.4 — Alert when logging breaks3.3.5 — Correlate and review your logs3.3.6 — Reduce logs and generate reports3.3.7 — Synchronize clocks for time stamps3.3.8 — Protect your logs from tampering