Access logs capture user identity, timestamp, resource accessed, and action taken. Retention periods are configurable and frequently shorter than the period over which incidents are discovered.

Logs should be protected against modification by the users they record.

Alternative Names:

Access Logging Record, User Access Log

Why it Matters?

Logs are what allow an organization to scope an incident rather than assume the worst, and the difference is substantial: a firm that can establish exactly which matters a compromised account accessed notifies narrowly, while one without logs must notify every client. Retention configuration determines whether that capability exists when needed, since incidents are frequently discovered months after they occur.

Frequently Confused with

Related terms

Frequently asked questions

Why do access logs matter after an incident?

Why do access logs matter after an incident?

Because they allow scoping to the matters actually accessed, while their absence forces notification to every client whose data the account could reach.

What retention period is adequate?

What retention period is adequate?

Long enough to cover the interval between compromise and discovery, which is frequently months, making twelve months a common minimum.