Meaning
Data recording methods that prevent the alteration or deletion of audit trails provide immutable evidence of transactions for regulatory audits and forensic investigations. This worm storage logging uses write once read many technology to ensure that once a record is created, it cannot be changed by any user. The definition covers the hardware and software locks that protect the integrity of the log files.
It ensures that the history of the system is a true account of all actions taken. This level of security is a requirement in the financial and healthcare industries.
Storage Permanence
Physical or logical barriers prevent the rewriting of data sectors on the storage media. In a system using worm storage logging, the hardware rejects any command that attempts to delete an existing file or modify its contents. This permanence makes the records acceptable in a court of law.
Audit Path
Sequential records of every system event allow an investigator to reconstruct the timeline of a security breach. Through the use of worm storage logging, an organization can prove exactly who accessed a file and when the access occurred. This path remains visible even if the primary server is compromised.
Evidence Integrity
Proof of the original state of the data is maintained throughout the retention period. Secure archives protect the reputation of the company by providing an unalterable history of compliance.