TDA-02.14 ยท Logging Syntax

Control Description

Mechanisms exist to require system developers to use an industry-defined secure logging format to generate event logs for specified event types at organization-defined level of detail.

Control Question
Assessment question for control validation

Does the organization require system developers to use an industry-defined secure logging format to generate event logs for specified event types at organization-defined level of detail?

Control Weighting
8
Validation Cadence
Annual
NIST CSF Function
Detect
Supply Chain Risk Management (SCRM) Tiers
Applicable SCRM tier levels for this control
Tier 2 - Operational
Tier 3 - Tactical
Errata & Additional Notes

- new control