Skip to content
BCN-T2-NET-002Tier 2 · RegulatoryNetwork

Insufficient Logging and Retention

Security-relevant events are not captured, not centralised, or not retained for the required period.

Remediation SLA
30 days
Tier
2 · Regulatory
Domain
Network
Escalation
Security manager review at 14 days

What this finding is

Logging is absent, incomplete, or retained for less than the applicable requirement across network devices, cloud control planes, applications, and identity providers. The finding includes logs that exist locally but are not centralised, and centralised logs that lack integrity protection against modification by an attacker who reaches the host.

Why it is Tier 2

Every major framework mandates specific log content and retention periods — PCI DSS requires twelve months with three immediately available — and inadequate logging is among the most frequently cited audit deficiencies. The operational consequence appears during incident response, where absent logs mean the scope of a breach cannot be established, which under most notification regimes obliges you to assume the worst case and notify accordingly.

Most common misclassification

Absence of detection capability is often filed here. Missing IDS/IPS coverage is BCN-T2-NET-003; this finding concerns the capture and retention of records.

How to detect it

  1. 1Compare captured log sources against the applicable requirement, item by item; partial coverage is the norm and is what assessors find.
  2. 2Verify actual retention in the storage tier rather than the configured policy, and confirm logs remain queryable rather than merely stored.
  3. 3Confirm cloud control-plane logging (CloudTrail, Azure Activity, GCP Audit) is enabled in every region and account, including those that are unused.
  4. 4Test whether a host-level administrator can alter or delete that host's forwarded logs — if so, integrity protection is absent.

How to remediate it

Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.

  1. 1Enable control-plane logging organisation-wide with a policy that prevents disablement in individual accounts.
  2. 2Centralise into a store held in a separate account or subscription, with write-once semantics and no delete permission for operational roles.
  3. 3Set retention to the longest applicable requirement across every framework in scope, using tiered storage to control cost rather than shortening retention.
  4. 4Add the log sources the standard names explicitly — administrative actions, authentication events, and access to regulated data are the usual gaps.
  5. 5Document the logging architecture and evidence retention, since assessors test the documentation as well as the control.

How to verify the fix

A sampled security event is retrievable from centralised storage at the far end of the retention period, and an attempt to delete a log object from an operational role is denied.

Mappings

Attacker techniques

Compliance mappings

  • PCI DSS v4.0
    10.5.1 — twelve months retention, three immediately available
  • SOC 2
    CC7.2 — monitoring for anomalies
  • ISO/IEC 27001:2022
    A.8.15 — logging
  • HIPAA
    §164.312(b) — audit controls

Tools that surface this

PROWLERCloudsploitScoutSuite