Frameworks / CIS Controls v8 / CIS-8.2 CIS Controls v8
CIS Control 8: Audit Log Management
CIS Controls v8 CIS-8.2: Collect Audit Logs Gather audit logs, making sure logging has been switched on across enterprise assets as the audit log management process requires.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 99 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-2(12) Account Monitoring for Atypical Usage AU-12 Audit Record Generation AU-2 Event Logging AU-3 Content of Audit Records AU-5 Response to Audit Logging Process Failures AU-7 Audit Record Reduction and Report Generation AU-7(1) Automatic Processing AU-9 Protection of Audit Information CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) IR-5 Incident Monitoring PE-16 Delivery and Removal SA-1 Policy and Procedures SI-4 System Monitoring SI-4(23) System Monitoring | Host-based Devices (SI-4(23)) AC-2(12) Account Monitoring for Atypical Usage AU-12 Audit Record Generation AU-2 Event Logging AU-3 Content of Audit Records AU-5 Response to Audit Logging Process Failures AU-7 Audit Record Reduction and Report Generation AU-7(1) Automatic Processing AU-9 Protection of Audit Information CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) IR-5 Incident Monitoring PE-16 Delivery and Removal SA-1 Policy and Procedures SI-4 System Monitoring SI-4(23) System Monitoring | Host-based Devices (SI-4(23)) 10.2.1 10.2.1 Audit logging enabled on all system components 10.2.1.2 10.2.1.2 Logs capture all administrative actions 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program 5.3.4 5.3.4 Anti-malware audit logs enabled and retained 9.4.4 9.4.4 Management approval for media leaving facility NIST-CSF-DE.AE-03 Information is correlated from multiple sources NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring ISM-0582 Centralised Microsoft Windows event logging ISM-1963 Logging events from internet-facing network devices ISM-1977 Logging events for Linux 5.7 Threat intelligence 8.15 Logging 8.16 Monitoring activities 5.7.1 Monitoring, measurement, analysis and evaluation 6.9 Operations security 6.9.4 Logging and monitoring SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies ASBv3-DS-7 Enable logging and monitoring in DevOps LT-3 Enable logging for security investigation ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components SEC04-BP01 Configure service and application logging AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment A.6.2.6 AI system operation and monitoring Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CIS Control 8: Audit Log Management You are reading one control. How much of CIS Controls v8 have you already done? CIS Controls v8 CIS-8.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 99 it maps to, and the evidence behind each claim, over MCP and REST.