GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

MON-001 Audit Log Scope and Generation

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Security-relevant events are defined and logged across all production systems, applications, and cloud services. Log events include: authentication successes and failures, privilege use, administrative actions, data access and export, configuration changes, and system errors. Log scope is documented and reviewed at defined intervals.

Rationale

Logs are the primary evidence source for incident investigation, compliance audits, and forensic analysis. Undefined scope leads to gaps that cannot be reconstructed after the fact.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.312(b) makes audit controls a required standard over systems that contain or use electronic protected health information, so the documented log scope has to be demonstrably complete over those systems.

NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex point 3.2.3 lists twelve log sources and six are outside the usual security-event scope: relevant outbound and inbound network traffic, access or changes to critical configuration and backup files, use of system resources and their performance, physical access to facilities, access to and use of network equipment and devices, and the activation, stopping and pausing of the logs themselves. The list of assets to be logged is derived from the risk assessment rather than set directly.

Framework Mappings (19)

LOG-07Logging Scopefull
LOG-09Log Recordsfull
LOG-12Transaction/Activity Loggingpartial
LOG-13Access Control Logsinformative
LOG-07Logging Scopefull
LOG-09Log Recordsfull
LOG-12Transaction/Activity Loggingpartial
LOG-13Access Control Logsinformative
EU-AI-Art.12.1Logging and Record-Keeping — Automatic Event Logging Capabilityinformative
HIPAA-164.308.a.1.ii.DInformation System Activity Reviewinformative
HIPAA-164.308.a.5.ii.CLog-in Monitoringinformative
HIPAA-164.312.bAudit Controlspartial
8.15Loggingfull
NIS2-CIR-3.2Monitoring and Loggingpartial
AU-1Policy and Procedurespartial
AU-12Audit Record Generationfull
AU-2Event Loggingfull
AU-3Content of Audit Recordsfull
AU-3(1)Content of Audit Records | Additional Audit Informationfull

Evidence (2)

configurationtechnicalautomated

Logging configuration for production systems, applications, and cloud services showing security-relevant event categories are enabled, including authentication, privilege use, administrative actions, data access, configuration changes, and errors.

Example: AWS CloudTrail configuration showing management events and data events enabled for all production accounts; application logging configuration (e.g., log level and category settings in application config); GCP Audit Logs configuration export

Test: Review logging configuration for cloud platform and application services. Verify: (1) authentication successes and failures are logged; (2) privilege use and administrative actions are logged; (3) data access and export events are logged; (4) configuration changes generate log events; (5) cross-check against a live log stream in the SIEM and confirm events of each type are appearing.

policydocumentmanual

Audit logging scope policy or standard defining which event categories are required to be logged, where logs must be sent, and the review schedule for scope coverage.

Example: Audit Logging Policy or Security Monitoring Standard (version-controlled, approved within last 12 months) with an enumerated list of required event categories

Test: Request the audit logging policy. Verify: (1) required event categories are explicitly listed; (2) the document references all system types in scope (cloud platform, application, network, endpoint); (3) log forwarding requirements are specified; (4) the review schedule is defined and the last review was completed within the required interval.

Questions (2)

boolean

Is there a documented log scope naming the security-relevant events captured across production systems, applications and cloud services?

Log scope should be documented in a formal policy or standard. Gaps in event categories (e.g. no data access logging) are a common audit finding.

multi

Which event categories are captured in your production audit logs?

Authentication successes and failuresPrivilege use and role/permission changesAdministrative and configuration changesData access and data export eventsAPI requests (at least for sensitive endpoints)System and application errorsNetwork connection events (e.g. VPC flow logs)None of the above

All seven categories are expected for a complete audit logging posture. Missing data access or configuration change logging are the most common gaps in enterprise environments.