CYB-22 · Cyber security
Without adequate logging, incident investigation and forensic analysis is impossible. All critical systems must generate security event logs that are centralised, tamper-protected, and retained for a minimum of 12 months. Logs must include authentication events, privilege escalations, and data access events.
Trigger
No centralised log management; logs stored only on source systems (modifiable by attackers); logs retained for less than 12 months; authentication events not logged
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Implement centralised SIEM or log management (e.g., Microsoft Sentinel, Splunk, AWS CloudWatch Logs). Enable audit logging on all critical systems. Configure 12-month log retention. Protect logs from tampering (read-only storage).
Evidence required