Every topic through three lenses: policy, process, technical. Pick a family, then click any control to light up its mappings.
432 controls · 20 families · 2214 mapped pairs
Frameworks
Family
Lens
Sekit CSF · Cloud Security
ISO/IEC 27001:2022
Sekit CSF · Cloud Security · Policy
RCF-0343Cloud logging
The company formally requires that all significant cloud activity is logged and retained
ISO/IEC 27001:2022
This policy control states in writing which cloud activity must be logged and for how long, a documented operating requirement adjacent to the procedures A.5.37 covers for IT facilities.
Stating in writing which cloud activity must be logged and who is accountable gives A.8.15's logging requirement its scope in cloud environments.