Problem Definition
The organisation audit logs related to IP allowlisting is not sufficient to know what change was made (e.g. edited the name, before and after), what product was added/removed, on which site.
Suggested Solution
Please add all the details for any change in the IP allowlist in the organisation audit log entry. Examples are:
- Change of IP policy name, before and after
- Added/Removed product on the policy
- Added/removed site on the policy
- Added/removed IP address on the policy
Why this is important
This is important to track what has been changed and by who for security purposes. Currently, the information are not logged in detail.
It only shows "Edited <Policy Name> IP allowlist" which isn't helpful with auditing and security investigations.
Workaround
No workaround is available right now
- is related to
-
ACCESS-1763 [Tracking in Issue Links] Organisation-level audit log feature requests
- Gathering Interest
-
ACCESS-1839 Provide versioning and backup option for admin and product permission related configurations
- Gathering Interest
- was cloned as
-
ACCESS-1558 IP Allowlist audit log to include incident and IP address of blocked requests
- Gathering Interest