SRS-061: Audit Tampering Detection and Logging
Identifier​
SRS-061
Software System​
- Audit Service
- Security Anomaly Detection Service
- Monitoring & Alerting Service
Category​
- Security
- Data Integrity
Description​
The system shall provide a mechanism to immediately detect and log any attempt to alter or delete audit files, ensuring the integrity of the audit trail is actively monitored.
- Continuous integrity monitoring: The system shall continuously or periodically run an integrity check on the audit trail by verifying the cryptographic seals of the audit records.
- Automated alerting: If an integrity check fails, indicating a potential alteration or deletion of an audit record, the system shall immediately generate a high-priority security alert to notify designated administrators.
- Logging of tampering events: The detection of a potential tampering event shall itself be logged in a separate, secure, and high-visibility system log. This log entry must include details of the integrity failure, such as the timestamp of the detection and the specific audit record or batch that failed verification.
Derived from PRS​
PRS-0MC
: Comprehensive secure audit trails for user interactions