Tietojärjestelmien käytöstä ja tietojen luovutuksista kerätään riittävät lokitiedot.
Lisätiedot:
– lainsäädännön ja toiminnan vaatimukset on selvitetty ja toteutettu lokitus niiden mukaisesti
– huomioitava 17 § ja siitä annettu suositus
The development of system logs must keep pace with the development of the system and enable, for example, the necessary resolution of incidents. In connection with the data system list, we describe for which systems we are responsible for the implementation of the logging. For these systems, we document:
The Authority must ensure that the necessary logs are kept of the use of its information systems and of the disclosure of information from them, if the use of the information system requires identification or other log-in. The purpose of log data is to monitor the use and disclosure of data contained in information systems and to detect technical errors in the information system.
In Cyberday, the owner of the information system may be responsible for controlling the collection of log data from the information system. The organisation documents the content of the logs in more detail for those information systems for which it is responsible for technical maintenance. For other information systems, the owner, in cooperation with the system vendor, checks that the necessary logs are collected.