Skip to main content
← All controls
AU-2 / AU-3 / AU-6 / AU-9 / A.8.15 / CIS-8.2 / CIS-8.5 NIST SP 800-53 Rev 5

Access logging and audit

Demonstrate that all critical systems and applications generate, protect, retain, and review access logs capturing authentication events, authorization decisions, and resource access activities with sufficient detail to support security investigations and accountability.

Description

What this control does

Access logging and audit controls ensure that all access attempts, successful or failed, to systems, applications, and data are captured in tamper-evident logs with sufficient detail to identify who accessed what, when, from where, and what actions were performed. These logs must include timestamps synchronized to a reliable time source, user or process identifiers, source addresses, resource identifiers, and the outcome of each access attempt. Comprehensive access logging enables security monitoring, forensic investigation, compliance validation, and accountability enforcement across the IT environment.

Control objective

What auditing this proves

Demonstrate that all critical systems and applications generate, protect, retain, and review access logs capturing authentication events, authorization decisions, and resource access activities with sufficient detail to support security investigations and accountability.

Associated risks

Risks this control addresses

  • Unauthorized access goes undetected because no audit trail exists to identify intrusion attempts or successful breaches
  • Insider threats cannot be investigated or prosecuted due to insufficient logging of privileged user activities
  • Compliance violations occur when regulatory requirements for access logging and retention are not met
  • Attackers modify or delete audit logs to cover their tracks after compromising systems lacking log integrity protections
  • Security incidents cannot be reconstructed or root-caused because logs lack sufficient detail about user actions and system changes
  • Failed authentication attempts indicating brute-force or credential-stuffing attacks are not logged or analyzed
  • Excessive retention costs and privacy violations result from logging unnecessary sensitive data without proper log content filtering

Live threat patterns this control mitigates:

MEDIUM Alleged data breach of MHz Group A forum post claims that MHz Group, a UAE-based management consulting and software development company, suffered a data… MEDIUM Alleged data breach of Egyptian Maritime Transport & Logistics Sector The poster claims to have made available a leaked database from Egypts Maritime Transport & Logistics Sector, allegedly… MEDIUM Alleged data breach of automotive dealership group (M Group) A poster on UpDap claims to have leaked data from M Group, a multinational conglomerate and major General… MEDIUM Alleged leak of Israel Government documents A post claims to share over 200,000 documents (45GB) allegedly leaked from the Knesset of Israel and other… MEDIUM Alleged data breach of Iraq Popular Mobilization Forces (PMF) Officials The poster claims to have leaked a database of officials from Iraqs Popular Mobilization Forces (PMF) dating from… MEDIUM Alleged data breach of IMAJBET Turkish online casino A poster claims to have leaked a database of 42,000 users from IMAJBET, a Turkish online casino, including… MEDIUM Alleged data breach of Ashur University A threat actor leaked a database allegedly belonging to Ashur University (au.edu.iq) in Iraq, attributed to Anka Team,… MEDIUM Alleged sharing of collected Telegram member lists The poster claims to have collected Telegram members from groups and channels related to crypto, casino, freelance, NFT,… MEDIUM Alleged data breach of Privatization Holding Company (PHC.com.jo) The poster claims to have made available stolen source code from PHC.com.jo, a Jordanian energy and industry company,… MEDIUM Alleged data breach of ohn-law.com Israeli legal-case website MEDIUM Alleged data breach of thezebra.co.il MEDIUM Alleged sharing of Kuwait drivers license template/document MEDIUM Request for Telegram database (ID to phone number) A forum member requested a Telegram database mapping user IDs to phone numbers. No sale or leak has… MEDIUM Alleged data breach and leak of Qiam Real Estate (Saudi Arabia) The threat actor claims to have hacked qiam.com.sa, a Saudi Arabian real estate website, extracting its databases and… MEDIUM Alleged data breach and leak of Jawaharlal Nehru Technological University-affiliated… The actor claims to have hacked tahoor.ae, a college affiliated with Jawaharlal Nehru Technological University, extracting databases and… MEDIUM Alleged leak of Iraqi Ewane account data A forum post shares a Mega.nz link claiming to leak account data associated with Ewane in Iraq, gated… MEDIUM Alleged leak of EPS Tech R&D documents linked to Israeli Air Force A threat actor known as Handala claims to have leaked top-secret design documents for electronic equipment used by… MEDIUM Alleged data breach of Axcera.io A forum post claims Axcera, a fintech infrastructure provider operating in the UAE and Cyprus, was hacked by… MEDIUM Alleged leak of shib bet iran deek officers The threat actor claims to have leaked a dataset associated with Shin Bet, specifically targeting personnel linked to… MEDIUM Alleged data breach of Al-Ayen University (alayen.edu.iq) A threat actor leaked an alleged database from alayen.edu.iq, an Iraqi university, containing records of doctors/staff including names,… MEDIUM Alleged source code leak of Al-Zaytoonah University of Jordan A threat actor is freely distributing what is claimed to be the source code of Al-Zaytoonah University of… MEDIUM Alleged data breach of Kocaeli Metropolitan Municipality employee database MEDIUM Alleged data breach of elexbet.com Turkish betting platform MEDIUM Alleged data breach of Turkish Freemasons Governance System MEDIUM Dallah Hospital possibly compromised by actor/group oaaaoxxz on May 31, 2026

Testing procedure

How an auditor verifies this control

  1. Obtain and review the organization's access logging policy and standards document identifying which systems, applications, and data categories require audit logging
  2. Select a representative sample of in-scope systems spanning infrastructure (servers, network devices), applications (databases, web applications, SaaS platforms), and security controls (firewalls, IAM systems)
  3. Review the logging configuration for each sampled system to verify that successful and failed authentication events, authorization decisions, and data access operations are captured
  4. Examine sample log entries from each system to confirm presence of required fields including timestamp, user identifier, source IP or hostname, target resource, action performed, and outcome status
  5. Verify that log timestamps are synchronized to a centralized authoritative time source (NTP server) by comparing log timestamps across multiple systems
  6. Test log integrity protections by attempting to modify or delete archived logs and confirming that write-once storage, cryptographic signing, or centralized log forwarding prevents tampering
  7. Review log retention schedules and verify that logs are retained for the period specified by policy, regulatory requirements, or contractual obligations through examination of archived logs
  8. Interview security operations or compliance personnel to confirm that access logs are periodically reviewed for anomalies and that documented evidence of log review activities exists for the audit period
Evidence required Configuration exports or screenshots showing enabled audit policies for authentication services, databases, operating systems, and applications including specific event categories logged. Sample log files or SIEM query results demonstrating actual log entries with complete timestamp, user, source, target, action, and outcome fields. Log retention policies, backup schedules, and evidence of centralized log collection infrastructure (syslog servers, SIEM platforms). Documented log review procedures and completed log review records or incident investigation reports demonstrating operational use of access logs.
Pass criteria All sampled critical systems generate access logs capturing authentication attempts, authorization decisions, and resource access with complete required fields; logs are protected against unauthorized modification; retention periods meet or exceed policy requirements; and documented evidence confirms regular review of logs by security personnel.