Audit logs capture authentication events, data access, downloads, permission changes, and administrative actions with timestamps and user identifiers. Logs should be tamper-resistant and retained for a defined period.
They serve detection, investigation, and demonstration of compliance.
Alternative Names:
Access Logging, Security Audit Log
Why it Matters?
Logs are what allow an organization to answer the question that follows any incident: what was actually accessed. Without them, a firm facing a suspected compromise must assume the worst and notify accordingly, which is far more damaging than a scoped notification supported by evidence. Retention periods matter, since incidents are frequently discovered months after they occur.
Frequently Confused with
Related terms
Frequently asked questions
What should audit logs capture?
How long should logs be retained?





