US-EPA-CAMD / easey-ui

Project Management repo for EPA Clean Air Markets Division (CAMD) Business Suite of applications
MIT License
0 stars 0 forks source link

Requirements for Audit Log for Data Changes #4732

Open MaeganWood64 opened 1 year ago

MaeganWood64 commented 1 year ago

Next steps:

Needs to be implemented before performance testing.

MaeganWood64 commented 1 year ago
JanellC commented 1 year ago

Need requirements for what needed to be audited. Mike H will send over requirements . Requirements will be sent week of 5/29

JanellC commented 1 year ago

Aiming to work on this after the ECMPS BETA functionality is completed

JanellC commented 10 months ago

@JanellC add requirements to this ticket for whoever picks this ticket up

mark-hayward-erg commented 1 month ago

@maheese Is this covered by #6246, or does additional logging need to be defined in this ticket (or other new tickets)?

maheese commented 1 month ago

@maheese Is this covered by #6246, or does additional logging need to be defined in this ticket (or other new tickets)?

6246 was intended to cover AC-6(9) which just deals with privileged functions. In our case we are defining these as any action that requires ECMPS Admin. Privileged audit records are called out separately in the controls.

This ticket was created to cover general audit requirements. Since this ticket was initially created we have received additional guidance on what event types need to have audit records. Here's what was provided:

For each event we are supposed to be capturing:

We should have a discussion and come to a consensus on what these mean for our system and then create additional tickets to implement.