Identities (users) have edit (write) access to centralised logging data without a confirmed need
Context and Guidance: The confidentiality and integrity of centralised logging data should be protected by restricting the identities (users) that have access. This ensures the logging data can be used to build an accurate chain of events when investigating a cybersecurity incident.