Skip to main content

SID-AUDIT-01 — Structured Security Event Logging

PropertyValue
Statusverified
Ownerplatform
Categorytechnical
CSF Functiondetect
GroupAudit and Monitoring Controls

Description

Production structured JSON logging via zap with named loggers per component. Trust evaluation audit logging: subject_id, resource_type, strategy, timing. AuthZEN proxy user attribution (user_id, tenant_id per evaluation request). Failed admin auth attempts logged at WARN level.

Components

  • Wallet Backend (Go)
  • Trust Service (AuthZEN)

Source References

Audit Findings

FindingSeverityStatus
EN-S-1 — Partial audit logging and SIEMmediumin progress
ISO-O-13 — Partial incident assessment and evidence handlingmediumopen
ISO-P-2 — Partial security event reportinglowopen
ISO-T-7 — Partial logging and monitoringmediumopen