Organization should establish an audit log management process
High
Azure
General
manual-cis-audit-log-management
How to fix it
Establish and maintain an audit log management process. Define which events to log, retention periods, and log review procedures. Ensure logs are protected from tampering.
How to verify
- Verify audit log management policy exists
- Confirm log retention meets requirements
- Verify periodic log review records
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related Azure rules
- Action Group should be enabled
- Activity Log Alert should be enabled
- AKS cluster logs should be sent to Log Analytics
- AKS cluster must enable RBAC
- AKS cluster must enable RBAC
- AKS cluster should be a private cluster
- AKS cluster should disable local accounts
- AKS cluster should enable Azure RBAC for Kubernetes