← Inspection rules

SEC-009 / v1.2.0 / 2026-10-02

Inspect coverage of access and administration logs

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Environments supporting file access, bulk exports, credential issuance, or administrative actions.

Where to look first

  • Audit event types, retention, query coverage
  • Direct file access, credential creation, anomalous login alerts

Inspection steps

  1. Use synthetic events to verify that UI and direct API paths are both logged.
  2. Verify alerts for bulk access and unexpected administration without logging secrets or personal data.

Remediation direction

  • Add missing event coverage and alerts; define retention and investigation ownership.

Evidence required for completion

  • Record synthetic event execution, collection, query, and alert delivery.

Limits and unverified scope

  • Missing logs do not establish absence of compromise. Unavailable logs mean unverified.