NIST SP 800-92 NISTSP92-4: Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
Operate log management functions per NIST SP 800-92 Chapter 5 (Operational Processes) + Section 5.5 (Confidentiality, Integrity, and Availability of Logs). Time synchronisation per Section 5.6: deploy NTP (or equivalent) infrastructure with redundant authoritative sources + stratum hierarchy + drift monitoring + alerting + timezone normalisation in central log store (UTC preferred). Log parsing and normalisation per Section 5.7: parse incoming logs to a common schema (Common Event Format + Elastic Common Schema + or vendor schema) + maintain parser catalogue + versioning + test framework + monitoring for parsing failures. Log storage capacity planning per Section 5.8: tiered storage matching access pattern (hot for current incidents + warm for routine query + cold for retention + archive for long-term legal/regulatory) with capacity monitoring + scale triggers + cost optimisation. Log integrity protection per Section 5.9: write-once-read-many storage where regulator requires + cryptographic hash chains or signatures + tamper-evident logs + access logging on log management systems + separation of duties between log producers and log administrators. Access control to log data per Section 5.10: role-based access (analyst + admin + auditor + investigator + privileged + read-only) + MFA + just-in-time elevation where appropriate + access logging + periodic access review. Privacy and data minimisation in logs per Section 5.11: avoid logging sensitive content (passwords + tokens + cardholder data + PII beyond purpose) + redact at source where feasible + apply pseudonymisation for analytical use where applicable.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 236 controls across 76 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021