UK NCSC Cyber Assessment Framework
Objective C: Detecting cyber security events – UK NCSC Cyber Assessment Framework

UK NCSC Cyber Assessment Framework C1.b: C1.b Securing logs

Log data is held securely, accessible only with a business need, and deleted after a suitable retention period. Partially achieved: only authorised users and systems access logs, access is partly monitored, retention periods are defined, and legitimate reasons for access are set out. Achieved: the logging architecture protects itself from threats comparable to those it detects, analysis uses copies leaving the master intact, every action on log data is attributable, and log integrity is protected with modification or deletion detected and attributed.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Objective C: Detecting cyber security events – UK NCSC Cyber Assessment Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.