▲
6
Do I need to log who read the logs?
10.2.1.3 mentions access to audit logs. Does that really mean an audit trail of the audit trail?
10.2.1.3 mentions access to audit logs. Does that really mean an audit trail of the audit trail?
Yes, and it is less circular than it sounds. Somebody with log access could read things they should not, or check what evidence exists before deciding what to do next. Recording who looked is how you catch that.
Practically it means individual accounts on the log platform. If everyone shares one login to the SIEM this requirement is not met regardless of what the SIEM records.