Section 74 of 101
73. Audit and Engineering Logs
Stable section ID: S05-CON-006-SECTION-74 · 43 content blocks
Audit and Engineering Logs provide a durable record of actions, decisions, changes, observations, and evidence affecting the building.
Audit Logs shall record:
authentication attempts;
authorization decisions;
configuration access;
commands;
overrides;
policy changes;
software updates;
credential changes;
remote access;
security incidents;
administrative actions.
Engineering Logs shall record:
commissioning;
configuration changes;
compatibility decisions;
inspection;
maintenance;
faults;
repairs;
test results;
capacity restrictions;
Interface connection and disconnection;
Profile changes;
engineering approvals.
Each log entry shall include:
unique record identity;
timestamp;
actor;
action;
affected entity;
previous and resulting condition;
reason;
authorization;
configuration version;
evidence reference;
outcome.
Logs shall be append-only after acceptance. Corrections shall reference the original entry and preserve both records.
Retention requirements shall reflect safety, regulatory, lifecycle, warranty, security, and engineering needs.
Access shall be role-controlled. Privacy-sensitive information shall be separated or minimized while preserving necessary engineering accountability.
The BIOS shall support export in a documented format so that lifecycle history is not trapped within one vendor platform.
Clock uncertainty, offline entry, delayed synchronization, and imported historical records shall be identified explicitly.