Using the audit log
Find out who did what, and when, to respond to an inspection or an incident.
ObjectiveBy the end of this lesson, you will be able to find out in the audit log who did what and when, and turn it into a documented monthly review.
The audit log records the organisation’s administration and security events. It answers the question that always comes up after the fact: who did what, and when? It is your first source during an internal audit, a question from the data protection officer or an incident.
What you look for in it
- An account’s sign-ins and failed sign-ins.
- Members added and removed, and role changes.
- Changes to the console: assistants, skills, tools, restrictions.
- Changes to the authentication configuration.
Approvals, on the user side
The audit log covers administration. Decisions taken in day-to-day work are read elsewhere: each user’s “Activity” screen keeps what each task produced, its effects and the history of approvals. During an investigation, the two sources complement each other.
- Open the audit log from the organisation’s administration.
- Narrow the view to the period concerned.
- Then narrow it to the account or event type you are looking for.
- Note the relevant events with their date and author.
- Attach this extract to the incident or inspection file.
A routine rather than an emergency
Do not wait for an incident to open the log. A fifteen-minute monthly review is often enough: unexpected role changes, settings changed outside the procedure, repeated failed sign-ins on the same account. Anything surprising deserves a question to the person concerned before you draw any conclusion.
Keep review extracts in a Drive folder reserved for administrators. During an inspection, you will then show not only the log but also proof that it is read regularly.