← Inspection rules
SEC-009 / v1.2.0 / 2026-10-02
Inspect coverage of access and administration logs
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Environments supporting file access, bulk exports, credential issuance, or administrative actions.
Where to look first
- Audit event types, retention, query coverage
- Direct file access, credential creation, anomalous login alerts
Inspection steps
- Use synthetic events to verify that UI and direct API paths are both logged.
- Verify alerts for bulk access and unexpected administration without logging secrets or personal data.
Remediation direction
- Add missing event coverage and alerts; define retention and investigation ownership.
Evidence required for completion
- Record synthetic event execution, collection, query, and alert delivery.
Limits and unverified scope
- Missing logs do not establish absence of compromise. Unavailable logs mean unverified.