Control Packs · OBS-004 · v1.0.0
Records That Survive and Can Be Relied On
Decide how long the record has to answer questions, keep it where losing the system does not lose the record, and stop the account that acted from editing its own trail.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Confirm how long records must remain answerable, keep them where the failure they describe cannot erase them, and separate the authority to act from the authority to change the record of acting.
- The record you need is gone, or the person involved could change itThe events were recorded and are still useless: rolled over before anyone looked, lost with the system they described, or editable by the account whose actions they describe.
Versioned applicability rule
{
"any": [
{
"characteristic": "CONSEQUENTIAL_ACTION",
"equals": true
},
{
"characteristic": "PRIVILEGED_ACTION",
"equals": true
},
{
"characteristic": "SENSITIVE_DATA",
"equals": true
}
]
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- How far back should you be able to answer a question about what the system did?Problems are usually noticed long after they start. This number decides where records live and what they cost, and it is a poor thing to discover during an investigation.OBS-004-Q1 · threshold
- Who can change or delete the record of an action?If the account that performs an action can also edit its trail, the record cannot answer the one question it exists for.OBS-004-Q2 · choice
Requirements for the coding agent
- OBS-004-R1Retain records for the confirmed period, keep them somewhere the failure they describe does not also destroy, and make an expiry that removes them a deliberate, recorded action rather than a silent rollover.
- OBS-004-R2Enforce the confirmed separation between acting and altering the record of acting, so an account cannot remove or rewrite the evidence of its own actions without that removal itself being recorded.
Tests and evidence to retain
- RECORD_RETENTION_TESTAsk the record store for an event older than the confirmed period minus one day and verify it is still answerable.
- RECORD_INTEGRITY_TESTAttempt to edit or delete an action record as the account that performed the action and verify it is refused, or that the attempt is itself recorded where that account cannot reach.
- configuration_or_policy
- implementation_location
- test_result
- operational_procedure
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- AU-9 · Protection of Audit InformationNIST_SP_800_53_5_2_0 · partially addressesSeparating the authority to act from the authority to alter the record addresses protection of audit information at the design boundary. It does not cover cryptographic protection, backup of audit records, or operational access review.
- AU-11 · Audit Record RetentionNIST_SP_800_53_5_2_0 · partially addressesConfirming a retention period and making expiry deliberate addresses retention as a design decision; it does not establish an organization-wide records schedule or legal-hold handling.
- AU-4 · Audit Log Storage CapacityNIST_SP_800_53_5_2_0 · partially addressesRequiring that records survive the period they are meant to answer for touches storage capacity planning only insofar as a silent rollover is refused.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_AUDITABILITY
- Cyber Safety Review Board (via CISA) — Review of the Summer 2023 Microsoft Exchange Online IntrusionINC_TOKEN_FORGERY_INTRUSION_2023
- Uber Newsroom — Security UpdateINC_PRIVILEGED_CREDENTIAL_BREACH_2022