Audit Logging

Audit Logging

Audit Logging

Audit logs capture authentication events, data access, downloads, permission changes, and administrative actions with timestamps and user identifiers. Logs should be tamper-resistant and retained for a defined period.

They serve detection, investigation, and demonstration of compliance.

Alternative Names:

Access Logging, Security Audit Log

Why it Matters?

Logs are what allow an organization to answer the question that follows any incident: what was actually accessed. Without them, a firm facing a suspected compromise must assume the worst and notify accordingly, which is far more damaging than a scoped notification supported by evidence. Retention periods matter, since incidents are frequently discovered months after they occur.

Frequently Confused with

Related terms

Frequently asked questions

What should audit logs capture?

What should audit logs capture?

Authentication events, data access and downloads, permission and configuration changes, and administrative actions, each with user identity and timestamp.

How long should logs be retained?

How long should logs be retained?

Long enough to investigate incidents discovered well after the fact. Twelve months is a common baseline, and longer retention is often required by client agreements.