<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Secure_Req_14</id>
	<title>Secure Req 14 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Secure_Req_14"/>
	<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Secure_Req_14&amp;action=history"/>
	<updated>2026-04-16T10:20:49Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>https://wiki.idesg.org/index.php?title=Secure_Req_14&amp;diff=6592&amp;oldid=prev</id>
		<title>Omaerz: 8 revisions imported: Initial Upload of old pages from IDESG Wiki</title>
		<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Secure_Req_14&amp;diff=6592&amp;oldid=prev"/>
		<updated>2018-06-28T04:03:34Z</updated>

		<summary type="html">&lt;p&gt;8 revisions imported: Initial Upload of old pages from IDESG Wiki&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;lt;&amp;lt; Back to [[Baseline_Functional_Requirements_v1.0|Baseline Functional Requirements Index]]&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== SECURE-14.    SECURITY LOGS ==&lt;br /&gt;
Entities conducting [[IDEF Glossary DIGITAL IDENTITY MANAGEMENT FUNCTIONS|digital identity management functions]] MUST log their transactions and security events, in a manner that supports system audits and, where necessary, security investigations and regulatory requirements.  Timestamp synchronization and detail of logs MUST be appropriate to the level of risk associated with the environment and transactions.&lt;br /&gt;
&lt;br /&gt;
=== SUPPLEMENTAL GUIDANCE ===&lt;br /&gt;
Transactions and events associated with systems that support identity management functions must&lt;br /&gt;
be time-stamped and logged. Where necessary additional information related to the events also must&lt;br /&gt;
be logged (such as the source of an authentication assertion) with the data needed to support audits.&lt;br /&gt;
&lt;br /&gt;
Selection of logging and timestamping standards, processes, and procedures should be consistent&lt;br /&gt;
with the processes outlined in [[Secure Req 1|SECURE-1 (SECURITY PRACTICES)]].&lt;br /&gt;
&lt;br /&gt;
Audit records and logs must be protected consistent with [[Secure Req 2|SECURE-2 (DATA INTEGRITY)]].&lt;br /&gt;
&lt;br /&gt;
=== REFERENCES ===&lt;br /&gt;
As an example: HIPAA Security Regulations regarding development and maintenance of logging&lt;br /&gt;
procedures and records: 45 CFR Part 164, § 164.308(a)(1)(ii)(D), § 164.408(c):&lt;br /&gt;
http://www.ecfr.gov/cgi-bin/text-idx?node=pt45.1.164&amp;amp;rgn=div5&lt;br /&gt;
&lt;br /&gt;
=== APPLIES TO ACTIVITIES ===&lt;br /&gt;
[[IDEF Functional Model REGISTRATION|REGISTRATION]], &lt;br /&gt;
[[IDEF Functional Model CREDENTIALING|CREDENTIALING]], &lt;br /&gt;
[[IDEF Functional Model AUTHENTICATION|AUTHENTICATION]], &lt;br /&gt;
[[IDEF Functional Model AUTHORIZATION|AUTHORIZATION]], &lt;br /&gt;
[[IDEF Functional Model INTERMEDIATION|INTERMEDIATION]]&lt;br /&gt;
&lt;br /&gt;
=== KEYWORDS ===&lt;br /&gt;
[[IDEF Keywords AUDIT|AUDIT]], [[IDEF Keywords LOGS|LOGS]], [[IDEF Keywords PROCESS|PROCESS]], [[IDEF Keywords SECURITY|SECURITY]]&lt;br /&gt;
----&lt;br /&gt;
----&lt;br /&gt;
Quick Links:   [[SALS]]  |  [[Baseline Functional Requirements v1.0]]  |  [[Glossary]]  |&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Omaerz</name></author>
	</entry>
</feed>