P1-REQ-13-8-004

Logs SHALL NOT be treated as Evidence unless they are captured, preserved, and traced to a claim or review purpose.

Part 1, Section 13.8: Evidence Requirements.

Logs often contain useful recorded information, but logs do not automatically qualify as Evidence. A log becomes Evidence only when it is captured, preserved, and traced to the claim or review purpose it supports.

This requirement prevents uncontrolled logs, incidental runtime output, or temporary diagnostic material from being treated as governed Evidence without preservation and traceability.

This requirement applies to logs that are proposed, referenced, or used as Evidence.

It applies specifically to:

  • Runtime logs
  • Application logs
  • System logs
  • Audit logs
  • Diagnostic logs
  • Captured log extracts
  • Preserved log records

Verification SHALL confirm that logs are not treated as Evidence unless they are captured, preserved, and traced to a claim or review purpose.

Verification activities include review checks confirming that:

  • Logs used as Evidence have a capture record
  • Logs used as Evidence have a preservation record
  • Logs used as Evidence trace to a claim or review purpose
  • Logs without capture, preservation, and traceability remain operational or diagnostic material

Related source section:

Related requirement identifiers:

Draft


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/99_annexes/annex-d-requirements/part-01/p1-req-13-8-004/start.txt
  • Last modified: 2026/07/11 12:57
  • by nick_dido