What Gets Logged
Every user action across every module is written to the Activity Log automatically. no configuration required. Requirements assessments, status changes, evidence uploads, POA&M updates, SSP exports, policy generations, training completions, visitor sign-ins, maintenance records, configuration changes, and user account modifications all produce log entries. Each entry captures the user, the action, the affected record, and the precise timestamp.
The log is not limited to compliance-specific actions. System access events. logins, logouts, failed authentication attempts. are also captured. This means the Activity Log serves dual purpose: it satisfies AU domain requirements for audit trail creation and retention, and it provides the access accountability record that supports AC and IA domain controls.