← All findings
f-013 — Audit log tampering — DELETE /audit-logs/{id}
high · admin-panel · status open · first seen 2026-04-22
Framework mapping
| Framework | Controls / requirements |
|---|---|
| ISO/IEC 27001:2022 ISMS |
A.8.15 Logging |
| NIST SP 800-53 r5 Federal controls |
AU-9 |
| SOC 2 Type II Trust services |
CC7.2 |
| PCI DSS v4.0 Cardholder data |
10.5 |