Cybersecurity Glossary

Audit Log

The record of who did what and when, kept so that questions can be answered later.

What Audit Log means

Audit logs record sign ins, permission changes, file access, mailbox rules and administrative actions. Retention matters as much as collection: default retention in many cloud services is shorter than the time it typically takes to discover an intrusion.

Why Audit Log matters for small businesses and nonprofits

Without logs, an investigation cannot establish what was accessed, which usually forces you to assume the worst when notifying clients or regulators. Extending retention is often a small cost that changes the outcome of an incident entirely.

What to do about Audit Log

Three steps to deal with Audit Log

  • Turn on unified auditing in your cloud platform and confirm it is actually recording
  • Extend retention beyond the default, ideally to a year for identity events
  • Make sure logs cannot be deleted by the accounts they are recording

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.