Where the system can generate them, event logs for operating systems (and databases and networks where applicable) and gaming and entertainment applications track: failed logins; changes to live data files outside normal program and operating system execution (manual edits to gaming data files and tables); changes to policies and parameters (audit settings, password settings, security levels, players club point structures); an audit trail of administrator account activity with login name, date and time, event description and values before and after; and changes to the date and time on the master time server.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.