cds-snc / platform-forms-client

NextJS application that serves the public-facing website for Forms
https://forms-staging.cdssandbox.xyz/
MIT License
35 stars 13 forks source link

Login security control: Audit events #745

Open srtalbot opened 2 years ago

srtalbot commented 2 years ago

Instructions:

Link to the SRTM cell for each control is provided below. In each check list item it will identify the disciplines involved and provide links to the documentation that needs to be updated.

Acceptance criteria

Must

Should

srtalbot commented 2 years ago

@sarahhobson - need input from policy on log retention time. cc: @bryan-robitaille

sarahpiovesana commented 2 years ago

Could someone confirm if these logs only contain information about public servants that use the product?

srtalbot commented 2 years ago

We shouldn't be logging any end-user actions here - @jeberhardt @falila , could you confirm that's your understanding as well?

srtalbot commented 2 years ago

Please update this link with the audit information.

srtalbot commented 1 year ago

@craigzour, @bryan-robitaille - can you please update the link above with the logging information? Please provide code snippets showing that we capture the above logs.