Extends ISO/IEC 27002:2013 12.4.1. Event logs are reviewed on a stated, documented cycle to spot irregularities and propose fixes. Where possible, logs show whether an event changed PII (added, modified or deleted it) and who made the change; where several providers in different service categories are involved, the roles in doing this may differ or be shared. The processor decides and writes down the conditions under which the customer may receive or use log information, including the timing and the method, and shares those procedures with the customer; a customer allowed to reach logs the processor controls sees only records of its own activities and nothing about other customers.
This control maps to 7 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.