SSCP · Question #385
Which of the following questions are least likely to help in assessing controls covering audit trails?
The correct answer is B. Are incidents monitored and tracked until resolved? Audit trail controls are assessed by questions about their completeness, integrity, and protection: Does the trail capture user actions (A)? Is access to logs tightly controlled to prevent tampering (C)? Is there separation of duties to prevent a single person from both…
Question
Options
- ADoes the audit trail provide a trace of user actions?
- BAre incidents monitored and tracked until resolved?
- CIs access to online logs strictly controlled?
- DIs there separation of duties between security personnel who administer the access control
How the community answered
(45 responses)- A11% (5)
- B80% (36)
- C2% (1)
- D7% (3)
Explanation
Audit trail controls are assessed by questions about their completeness, integrity, and protection: Does the trail capture user actions (A)? Is access to logs tightly controlled to prevent tampering (C)? Is there separation of duties to prevent a single person from both committing and hiding actions (D)? These directly evaluate the audit trail itself. Whether incidents are monitored and tracked until resolved (B) pertains to incident response and management processes - a related but distinct security domain. Incident tracking uses audit trail data but evaluating the incident management process does not assess the quality or controls of the audit trail itself.
Topics
Community Discussion
No community discussion yet for this question.