Baseline Logging for Configuration Changes and Access Events, v1.0
Specifies requirements in accordance with the DHS CISA Secure-by-Design Pledge, published by the U.S. Dept of Homeland Security (DHS) Cybersecurity and Infrastructure Agency (CISA). Requires an organization to provide baseline logging for configuration changes, identity, network, and data access events, across all of its product and service offerings.
Assessment Step
1
Baseline Logging for Configuration Changes and Access Events (BaselineLoggingforConfigurationChangesandAccessEvents)
Across all of its product and service offerings, does the organization provide baseline logging for configuration changes, identity, network, and data access events?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Baseline Logging for Configuration Changes and Access Events
Across all of its product and service offerings, the organization must provide baseline logging for configuration changes, identity, network, and data access events.
Citation
SBDP
(doc)
|