LOG-11: Transaction/Activity Logging

Control Family:

Logging and Monitoring

CSF v1.1 References:

PF v1.0 References:

Info icon.

Control is new to this version of the control set and incorporates the following item from the previous version: EKM-02: Key Generation.

Control Statement

Log and monitor key lifecycle management events to enable auditing and reporting on usage of cryptographic keys.

Implementation Guidance

Logging of key lifecycle events should include but are not limited to the following events: key generation, key usage, key storage (including backup), and archiving and key deletion. In addition, only authorized personnel should have access to key materials, and all access attempts should be logged and reviewed. Document and implement all key-management processes and procedures for cryptographic keys, including:

  1. Generation of strong cryptographic keys
  2. Secure cryptographic key distribution
  3. Secure cryptographic key storage
  4. Key revocation after expiry
  5. Split knowledge and dual control as needed for manual key management operations
  6. Prevention of unauthorized substitution of cryptographic keys

Auditing Guidance

  1. Examine policy for logging and monitoring usage of cryptographic key usage lifecycle events.
  2. Examine the process to identify such events.
  3. Evaluate the review of these logs.

[csf.tools Note: For more information on the Cloud Controls Matrix, visit the CSA Cloud Controls Matrix Homepage.]

Cloud Control Matrix is Copyright 2023 Cloud Security Alliance.