CDP 35948454: Maintain System Administrator Log (app) #15
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
CDP Control ID:
35948454Category: Administrator Access
Frequency: Biannually
Owner: h.noerenberg
Parent: #1
Requirement & Guidance
Administrator Access Requirement: Maintain log of all Administrators as part of CDP Access Control Log. Administrators will then maintain an ACL that may contain additional details beyond what is in the engagement ACL (for example: User IDs; levels of heightened access). Attachment(s) Required Guidance: An administrator is a person who is responsible and has full access for the upkeep, and reliable operation of computer operating systems, databases, networks, and/or applications; the administrator may be involved with account creations, installations, and upgrades. Include administrators data in the Access Control log for client applications; record their User IDs and access privileges. Additional information can be found on CDP website Administrator Access
CapaKraken Action Plan — 35948454 System Administrator Log (ACL)
Scope: Zentrale Liste aller Admin-Accounts inkl. Privilege-Levels.
Aktueller Stand:
docs/acn-security-compliance-status.md3.2.7.01 OK — Activity History / Audit-Entries vorhandenUserRoletableTodos:
docs/cdp-access-control-log.md(neu)Dateien:
apps/web/src/app/(app)/admin/users/(Report-Feature)CapaKraken Compliance-Status
EAPPS-Mapping:
3.2.7.01 / 3.2.7.03Status: ✅ OK (laut
docs/acn-security-compliance-status.md)Zusammenfassung
Alle relevanten System-Admin-Aktivitäten werden via Activity History geloggt und sind über die Admin-UI einsehbar.
Nachweis
apps/web/src/app/(app)/adminHinweis (offener Restpunkt — separat zu tracken)
Log-Retention-Policy (wie lange speichern?) ist noch nicht formal dokumentiert — Follow-up im Logging Standard (siehe
docs/acn-standards-applicability.md#6).Entscheidung: Control ist nachweislich erfüllt → Ticket wird geschlossen.