E015—Log model activity
>Control Description
Application
Frequency
Every 12 monthsCapabilities
>Controls & Evidence (3)
Technical Implementation
Core - This should include:
- Capturing system activity details to support incident investigation and behavior explanation. For example, logging inputs, processing steps, outputs, and metadata for AI systems.
Core - This should include:
- Implementing log storage with appropriate retention periods, access controls, and data sanitation to support auditing and incident response.
Supplemental - This may include:
- Implementing technical controls to ensure logs are tamper-evident and independently verifiable. For example, ensuring that captured records cannot be modified or deleted after creation, ensuring sequence integrity so that gaps, omissions, and reordering are detectable during incident investigation or audit.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.