AU.L2-3.3.9Audit Management
Limit management of audit logging functionality to a subset of privileged users.
[a]
a subset of privileged users granted access to manage audit logging functionality is defined; and[b]
management of audit logging functionality is limited to the defined subset of privileged users.
Two named log administrators; analysts and engineers get read-only search
Implementation
AO coverage. Addresses both Audit Management objectives: the subset of privileged users allowed to manage audit logging functionality is defined, and management is limited to that subset.
Defined subset [a]. Two named individuals hold the log administrator role: the security lead and one platform engineer. The written definition also states what the role covers — ingest configuration, retention settings, detection rule changes, and role assignment within the platform — so there is no argument about which actions require it. A third person is trained and listed as the documented backup, eligible but not standing.
Limiting management [b]. Everyone else is read-only. Analysts search and build saved searches but cannot alter ingest or retention; application owners see their own source and nothing else. The default role granted at onboarding was changed to read-only, which is what actually fixed the drift — the prior state came from a default, not a decision.
Separation from the archive. Neither log administrator can delete from the write-once archive described in the AU.L2-3.3.8 example, so even the defined subset cannot destroy the record of what it did.
Activation and visibility. The backup administrator activates the role through time-bound eligibility with a ticket reference. Every action taken under the log administrator role is itself logged to the archive and reviewed weekly by someone who does not hold the role.
Maintenance. Quarterly attestation: export current platform role assignments, compare against the two named holders plus the eligible backup, and have the enclave owner sign. Offboarding or role change removes platform administration the same day.
Accepted gap. The outsourced provider occasionally needs platform administration for an upgrade. Access is granted as a time-bound activation on a named guest account for the change window, is session-recorded, and is revoked at window close rather than left standing.
What the evidence looks like
- Written role definition listing the two holders and what the role covers
- Platform role assignment export showing read-only for everyone else
- Default onboarding role configuration after the change
- Weekly review record of log-admin actions, signed by a non-holder
- Time-bound activation ticket and revocation record for the last provider upgrade
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.