Audit logs need protected access

The logs recording who did what are also the record of what an attacker did, which makes them a target rather than just a resource.

If the same administrators who can act can also delete the record of acting, the audit trail proves very little. Write-once storage, separate access and alerting on log deletion are what turn a log into evidence. It is the difference between a record and a courtesy.

More on Logging and telemetry