Audit and Accountability
Audit and Accountability
Section titled “Audit and Accountability”Authorized By: Chief Information Security Officer (CISO)
Purpose/Overview
Section titled “Purpose/Overview”Maintaining detailed audit logs is critical to managing and tracking the chronological flow of data from sources to destinations. In instances of security and compliance, audit logs offer an official record that can provide valuable insights that are beneficial to Safire’s interests. This policy outlines the procedures and standards in place to ensure proper audit logs are maintained. Additionally, these logs will ensure accountability of processes and personnel by tracking privileged functions performed.
This policy applies to all company officers, directors, employees, agents, affiliates, contractors, consultants, advisors or service providers that possess, access, or manage information owned by Safire. It is the responsibility of all the above to familiarize themselves with this policy and ensure adequate compliance with it.
This policy covers all information systems, applications, network devices, and infrastructure components that process, store, or transmit Safire data, including:
- On-premises systems and servers
- Cloud-based systems and services
- Network infrastructure devices
- Security appliances and tools
- Workstations and endpoints (Note: Any endpoint incapable of logging due to technical limitations must be documented in a System Security Plan (SSP) or Plan of Action and Milestones (POAM)).
- Applications processing sensitive or CUI data
Policy
Section titled “Policy”Audit Log Creation and Retention
Section titled “Audit Log Creation and Retention”Safire will create and retain system audit logs and records to the extent needed to enable the following for unlawful or unauthorized system activity:
- Monitoring
- Analysis
- Investigation
- Reporting
Actions of individual system users will be uniquely traced to such users to ensure they can be held accountable for their actions. This requires:
- Unique user identifiers (no shared accounts for access to systems processing sensitive data)
- Accurate timestamp information synchronized to an authoritative time source
- Sufficient detail to reconstruct events and identify responsible parties
Audit Log Review and Monitoring
Section titled “Audit Log Review and Monitoring”It is Safire’s duty to review and update logged events to ensure continued relevance and effectiveness.
Review Requirements
Section titled “Review Requirements”- Audit logs shall be analyzed weekly using automated tools, SIEM dashboards, or manual sampling to identify anomalous behavior.
- Critical system and security alerts shall be reviewed daily.
- If Safire leverages a Security Incident Event Monitoring (“SIEM”) tool or Security Operations Center (“SOC”) to automate such review, the CISO, IT or Compliance shall be informed of all detected anomalies within twenty-four (24) hours of their discovery.
- The CISO, IT or Compliance shall treat each such anomaly as a potential incident under Safire’s Data Breach Incident Response Plan and shall document the review, analysis, and disposition of each anomaly
Audit Logging Failure Response
Section titled “Audit Logging Failure Response”- In the event of an audit logging process failure, the CISO, IT and Compliance will be alerted immediately through automated alerting mechanisms.
- Critical system functions that depend on audit logging may be suspended until logging functionality is restored, at the discretion of the CISO or Chief Executive Officer, weighing security risks against operational impact.
- All audit logging failures shall be documented, investigated, and reported to the Approval Authority within 24 hours .
Auditable Events
Section titled “Auditable Events”Logs shall be created whenever any of the following activities are requested to be performed by the system:
-
Create, read, update, or delete confidential information, including confidential authentication information such as passwords;
-
Create, update, or delete information not covered in #1;
-
Initiate a network connection;
-
Accept a network connection;
-
User authentication and authorization for activities covered in #1 or #2 such as user login and logout (both successful and failed attempts);
-
Grant, modify, or revoke access rights, including:
-
Adding a new user or group
-
Changing user privilege levels
-
Changing file permissions
-
Changing database object permissions
-
Changing firewall rules
-
User password changes (including password resets)
-
System, network, or services configuration changes, including:
-
Installation of software patches and updates
-
Other installed software changes
-
Changes to security controls or monitoring tools
-
Application process startup, shutdown, or restart;
-
Application process abort, failure, or abnormal end, especially due to:
-
Resource exhaustion or reaching a resource limit or threshold (such as for CPU, memory, network connections, network bandwidth, disk space, or other resources)
-
The failure of network services such as DHCP or DNS
-
Hardware fault
-
Detection of suspicious/malicious activity such as from:
-
Intrusion Detection or Prevention System (IDS/IPS)
-
Anti-virus system
-
Anti-spyware system
-
Data Loss Prevention (DLP) tools
-
Anomalous user behavior detection systems
Audit Log Content Requirements
Section titled “Audit Log Content Requirements”At a minimum, audit logs shall contain:
- Date and time stamp (synchronized to authoritative time source)
- User identification (unique identifier)
- Source (IP address, workstation, device identifier)
- Event type and description
- Success or failure indication
- Object or resource accessed
- Severity or priority level (where applicable)
Personnel/Roles to be Alerted in Case of Audit Logging Process Failure
Section titled “Personnel/Roles to be Alerted in Case of Audit Logging Process Failure”The following personnel shall be notified immediately upon detection of audit logging failures:
- IT Director
- CISO
- Incident Response Team Lead
- IT Systems Owner/Administrator
- Compliance
Human Resources shall be notified if the failure appears to involve intentional tampering or sabotage.
Audit Analysis and Correlation
Section titled “Audit Analysis and Correlation”For the purpose of investigation and response to indications of suspicious activity, Safire will correlate data between:
- Audit record reviews
- Audit record analysis
- Audit record reporting processes
- Security tool alerts (IDS/IPS, anti-malware, DLP, etc.)
- Threat intelligence feeds
- External incident notifications
Safire will provide audit record reduction and report generation to support on-demand analysis and reporting as well as scheduled reporting to management and the Approval Authority.
Time Synchronization
Section titled “Time Synchronization”Safire will provide a system capability that compares and synchronizes internal system clocks with an authoritative source (e.g., NIST Internet Time Service, GPS-based time source) to generate accurate time stamps for audit records.
- All systems shall synchronize time at least hourly
- Time synchronization failures shall generate alerts to the Head of IT and Compliance Lead.
- Time sources shall be documented and reviewed annually
Protection of Audit Information
Section titled “Protection of Audit Information”Safire requires that audit information and audit logging tools are protected from unauthorized access, modification, and deletion through:
- Access controls limiting audit log access to authorized personnel only
- Integrity controls (e.g., cryptographic hashing, write-once storage) to detect unauthorized modifications
- Secure transmission of logs to centralized logging systems
- Redundant storage and backup of audit logs
- Physical and logical separation of audit functions from audited systems where feasible
Audit logging functionality is to be limited to a subset of privileged users specifically authorized by the Approval Authority. These users shall be:
- Documented in an access control list maintained by the IT Director
- Subject to additional background checks and monitoring
- Required to use multi-factor authentication
- Reviewed quarterly for continued need and appropriateness
Audit Log Retention
Section titled “Audit Log Retention”Audit logs shall be retained in accordance with the following schedule:
- System and application logs: Minimum 3 months online; 1 year total (archived)
- Security event logs: Minimum 3 months online; 1 year total (archived)
- Authentication logs: Minimum 90 days online; 3 years total (archived)
- Logs related to incidents, investigations, or Legal Hold: Retained until the matter is fully resolved plus 7 years.
- Logs containing CUI: Retained in accordance with NIST 800-171 requirements and contract specifications (minimum 3 years).
Retention periods may be extended by legal hold, litigation, regulatory investigation, or by direction of the Approval Authority.
Prohibited Actions
Section titled “Prohibited Actions”The following actions regarding audit logs are strictly prohibited unless explicitly authorized by the Approval Authority for legitimate business purposes:
-
Disabling or circumventing audit logging mechanisms
-
Modifying or deleting audit logs
-
Tampering with time synchronization
-
Sharing audit log access credentials
-
Exfiltrating audit logs to unauthorized locations
-
Using shared or generic accounts to perform auditable activities (except for specific system accounts documented and approved)
Compliance
Section titled “Compliance”Compliance Measurement
Section titled “Compliance Measurement”The policy owner will verify compliance through methods such as business tool reports and internal and external audits. Oversight is provided by CISO, IT, and Compliance functions. The CISO has the authority to temporarily restrict access to systems or data for any entity found to be noncompliant with this policy, pending final disposition by the CEO.
Exceptions
Section titled “Exceptions”Any exceptions must be approved by the Policy Owner in advance.
Non-Compliance
Section titled “Non-Compliance”Personnel found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.
Any vendor, consultant, or contractor found to have violated this policy may be subject to sanctions up to and including removal of access rights, termination of contract(s), and related civil or criminal penalties.
Related Standards, Policies, Plans, and Procedures
Section titled “Related Standards, Policies, Plans, and Procedures”- Access Control Policy
- Acceptable Use Policy
- Data Breach Incident Response Plan
Definitions
Section titled “Definitions”| Term | Definition |
|---|---|
| Audit | An official inspection of an account, generally by an external party. |
| Authentication | The verification of a user or processes identity |
| Authorization | The specific access rights and privileges of a user or process |
| CUI (Controlled Unclassified Information) | Unclassified Information that should not be publicly disclosed |
Referenced Terms
- CUI
- Information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies.
Revision History
- 2026-08-20 — Darren Rush
- Merge pull request #2 from safire-dev/dev (
16cb681)