Data access logs need object context

Recording that somebody accessed a record is much less useful than recording which record.

"User viewed customer data" cannot distinguish a support agent doing their job from one looking up a celebrity. Logging the object, and ideally the reason, is what makes misuse detectable. Many systems log the action and not the target, which produces an audit trail that cannot answer the question it exists for.

More on Data security