id: "SA-15(13)" title: "Logging Syntax" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-15.13" priority: "P1" implementation_level: "organization" parent: "SA-15" enhancement: True


Statement

Require the developer of the system or system component to minimize the use of personally identifiable information in development and test environments.

Guidance

In support of better incident response and the ability to more quickly reconstruct security-related actions, identifying specific requirements for secure logging facilitates the ability to connect application-produced audit event logs with operational data. Event types are consistent with the event types defined in AU-02.

Assessment Objective

Determine if:

the developer of the system, system component, or system service uses {{ insert: param, sa-15.13_odp.01 }} to log {{ insert: param, sa-15.13_odp.02 }} at {{ insert: param, sa-15.13_odp.03 }}.

System and services acquisition policy;

solicitation documentation;

acquisition documentation;

service level agreements;

acquisition contracts for the system, system component, or system service;

requirements for logging format, event types, and level of detail;

documentation evidence of requirements for logging format, event types, and level of detail;

system security plan; other relevant documents or records.

Organizational personnel with system and service acquisition responsibilities;

organizational personnel with information security responsibilities;

system developer

Developer logs for the system, system component, or system service.