17
DraftS05-CON-010v0.1Source imported
Section 93 of 102
92. Audit Logging and Traceability
Stable section ID: S05-CON-010-SECTION-93 · 29 content blocks
System05 shall maintain tamper-resistant Audit Logs for security-relevant and operationally consequential activities.
Audit logs may include:
- Authentication attempts.
- Permission changes.
- Agent activation.
- Tool use.
- Data access.
- Commands.
- Approvals.
- Configuration changes.
- Overrides.
- Failed actions.
- Cybersecurity events.
- Sensitive-data access.
- Emergency actions.
- Update and rollback events.
Logs shall identify:
- Actor.
- Agent.
- Action.
- Target.
- Time.
- Authority basis.
- Result.
- Related event or task.
- Relevant version.
- Integrity status.
Audit access shall itself be controlled and logged. Logs shall not be modifiable by the same agent whose actions they record without independent protection and traceability.
Audit systems shall support investigation without retaining unnecessary private information.