Scope
This international standard proposes guidance on controlling the effectiveness of logging capabilities for the protection of data lifecycle. This standard can be applied to data life cycle log management, data security events monitoring and early warning, analysis and traceability, etc.
Purpose
As the basis of security verification and traceability analysis, log records generated by data processing activities is an important part of data security. However, the current log management, use and verification lack of normative guidance for the whole life cycle of data, and it is difficult to effectively find data security risks, trace and analyze data security incidents.
According to different data activities, the proposal provides guidance regarding the contents, use methods and protection strategies of log records in each stage of data life cycle, and propose log verification guidelines to improve the ability of organizations to monitor and discover data security risks, deal with and track data security incidents
Comment on proposal
Required form fields are indicated by an asterisk (*) character.