Security Audit Event Logging Contract Design

    1

    Designs immutable security audit logs: actor-action schemas, cryptographic hash chains, WORM storage, and non-repudiation.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Security Audit Event Logging Contract Design

    Example session with this skill installed

    Design tamper-evident security audit logging for our Core Treasury Settlement Engine.

    • Subject: treasury-settlement-engine v4.2 (run-id: treasury-audit-001) executing wire settlements up to $25M across SWIFT corridors.
    • Deciders: Lead Security Architect (Elena Rostova) and Chief Compliance Officer (Marcus Vance).
    • Incident: In AUD-8821, auditors investigating a disputed $14M transfer found an admin altered approval timestamps in PostgreSQL to hide an SLA breach, while app stdout logs rolled over after 14 days and leaked plaintext bank accounts.
    • Tension: DevOps proposed sending stdout logs to Elasticsearch with 30-day retention and relying on DB updated_at columns. Elena Rostova and Marcus Vance reject mutable logs as checkbox security and forbid implicit service-account authorization. They mandate an immutable audit record schema (initiator, effective actor, action, target, outcome, monotonic sequence), WORM-locked S3 storage (7-year retention), cryptographic SHA-256 hash chaining anchored daily, zero secrets in artifacts, and a transactional outbox ensuring zero unlogged settlements.

    Write the audit logging specification under docs/.

    • Read your context and instructions
    • Compiled the security audit event
    • Generated the UI component

    Wrote docs/architecture/tasks/banking-audit-001/audit-logging-design/audit-logging-contract.md. Complete security audit logging specification establishing CADF event schemas, SHA-256 cryptographic hash chains, S3 7-year WORM storage, and fail-closed non-repudiation guarantees.

    ---
    skill: audit-logging-design
    ---
    
    # Security Audit Event Contract: Core Banking Ledger [AUDIT-BANK-001]
    
    ## Summary
    
    This specification establishes the immutable security audit event logging architecture, cryptographic non-repudiation chain, and compliance custody contract for `core-ledger-audit-pipeline v2.0` under run ID `banking-audit-001`, governing 45 microservices and 2,200 audit events/second. It decisively eliminates the log tampering vulnerabilities and audit failures demonstrated in incident AUD-4819 (where a rogue insider altered mutable Elasticsearch records to conceal an unauthorized $1.2M ledger override). The contract enforces a standardized Cloud Auditing Data Federation (CADF) schema, sequential SHA-256 cryptographic hash chaining (creating a tamper-evident ledger where any intermediate deletion invalidates downstream signatures), automatic archival to Amazon S3 Object Lock in Compliance Mode (7-year WORM retention), and a strict fail-closed transactional guarantee for privileged actions.
    
    ## Detailed Description
    
    Standard operational logs (`stdout`, application logfiles) are optimized for ephemeral debugging and lack legal defensibility. They allow system administrators with root or database access to delete or backdate log entries. Security audit logging enforces cryptographic non-repudiation: establishing incontrovertible mathematical proof of *who* performed *what action*, on *which resource*, from *where*, and with *what outcome*.
    
    

    Privileged Ledger Action ($1.2M Admin Override)
    │
    ▼
    [ Audit Event Interceptor: Synchronous Transaction Boundary ]
    ├── 1. Actor Identity: Captures Subject ID, Okta MFA Token, Source IP
    ├── 2. Action & Target: ledger.entry.override on Account ACC-88129
    └── 3. Cryptographic Chain Linker:
    ├── Reads previous_event_hash
    └── Computes: current_hash = SHA256(prev_hash + sequence_num + payload)
    │
    ┌───────────────┴───────────────┐
    ▼ (Audit Write Confirmed) ▼ (Audit Write Fails / Times out > 500ms)
    Proceed to Commit Ledger Mutation [ TRANSACTION HARD ABORT (Fail-Closed) ]
    Emit Event to Ingestion Stream Rollback Database Transaction; Alert SecOps
    │
    ▼ (Kinesis Stream / Firehose)
    [ S3 WORM Compliance Vault: bank-audit-vault-prod ]
    └── S3 Object Lock: COMPLIANCE Mode (7-Year Immutable Retention)

    
    ### Criteria and weights
    
    | Criterion | Why it matters here | Weight | Source of the weight |
    |---|---|---|---|
    | Cryptographic Immutability & Tamper Evidence | Privileged insiders must be mathematically prevented from concealing unauthorized ledger modifications (AUD-4819). | 0.40 | David O'Reilly (CISO SecOps) |
    | Transactional Fail-Closed Guarantees | If the audit record cannot be durably committed, the financial transaction must never execute. | 0.30 | Elena Rostova (Financial Compliance) |
    | Non-Repudiation & Identity Attribution | Log entries must prove actor identity via signed MFA tokens and client certificate thumbprints. | 0.20 | SEC Rule 17a-4 Mandate |
    | Redaction of Customer Secrets at Source | Audit records must not log raw payment card numbers or user PINs while capturing administrative context. | 0.10 | PCI-DSS v4.0 Req 10.5 |
    
    
    ### Comparison
    
    | Audit Logging Strategy Candidate | Storage Immutability | Tamper-Evidence Mechanism | Transaction Coupling | Evaluation |
    |---|---|---|---|---|
    | Option A: Mutable Elasticsearch Indices | Mutable (Admin can edit) | None (Plain JSON lines) | Asynchronous (Fire-and-forget) | Rejected: Allowed AUD-4819 insider tampering; non-compliant. |
    | Option B: Database Audit Tables | Relational DB table | Database triggers only | Synchronous DB commit | Rejected: DBA root credentials allow `DROP TABLE` or row edits. |
    | Option C: Cryptographic Chaining + S3 WORM (Chosen) | S3 Object Lock COMPLIANCE | SHA-256 sequential hash chain | Synchronous fail-closed boundary | Selected: Defensible proof, zero root override, 7-year WORM. |
    
    
    ### Result
    
    Option C is selected. Sequential cryptographic hash chaining guarantees tamper evidence; S3 Object Lock in Compliance Mode guarantees legal immutability.
    
    ---
    
    ### Required Mechanisms
    
    #### 1. Structured CADF Audit Schema Contract [MC-AS-01]
    All security-relevant events must strictly conform to the CADF JSON contract:
    ```json
    
    ```json
    {
      "audit_version": "2.0",
      "sequence_number": 4829104,
      "timestamp_utc": "2026-09-15T18:00:00.123456Z",
      "actor": {
        "subject_id": "usr_ops_9921",
        "role": "ROLE_LEAD_SETTLEMENT_OPERATOR",
        "authenticated_via": "OKTA_FIDO2_MFA",
        "source_ip": "198.51.100.42",
    
    "user_agent": "Mozilla/5.0... (Corporate Laptop MDM-Cert: c4b1e...)"
    
      },
      "action": {
        "name": "ledger.account.manual_credit",
        "severity": "CRITICAL",
        "reason_ticket_id": "CHG-2026-8819"
      },
      "resource": {
        "resource_id": "acc_comm_881920",
        "resource_type": "BANKING_LEDGER_ACCOUNT",
        "before_state_hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
        "amount_cents": 120000000,
        "currency": "USD"
      },
      "outcome": "SUCCESS",
      "previous_event_hash": "7f8e3a2d4c1b9a0e6f5d8c3b2a1e0f9d8c7b6a5e4d3c2b1a0f9e8d7c6b5a4e3d",
      "event_hash": "a1b2c3d4e5f60718293a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e"
    }
    
    
    #### 2. Cryptographic Hash Chaining Specification [MC-HC-01]
    - **Chaining Algorithm**:
      $$\text{event\_hash}_N = \text{SHA256}(\text{event\_hash}_{N-1} \parallel \text{sequence\_number}_N \parallel \text{timestamp}_N \parallel \text{payload\_bytes}_N)$$
    - **Non-Repudiation Invariant**: An attacker attempting to modify, insert, or delete an event at index $N-k$ invalidates the cryptographic hash chain for all subsequent events $N-k+1 \dots N$, exposing tampering immediately during automated verification audits.
    
    #### 3. WORM Storage & 7-Year Custody Vault [MC-WS-01]
    - Target S3 Bucket: `s3://bank-audit-vault-prod-useast1`.
    - **Enforcement**:
      - `ObjectLockEnabled: true`
      - Mode: `COMPLIANCE` (WORM). Retention duration: **2,555 Days (7 Years)**.
      - Server-Side Encryption: `aws:kms` with Customer Managed Key whose key policy blocks deletion even by account root.
    
    #### 4. Transactional Fail-Closed Execution Boundary [MC-FC-01]
    - For all actions tagged `severity: CRITICAL` (e.g. manual ledger adjustments, wire releases, permission grants):
      1. The application transaction worker issues a synchronous write to the local audit forwarder.
      2. If the audit forwarder fails to acknowledge receipt within **500 ms**, the database transaction executes an immediate `ROLLBACK`.
      3. The business operation fails with `500 Internal Server Error` and diagnostic `ERR_AUDIT_LOG_COMMIT_FAILED`.
    
    ---
    
    ### Invariants and Contracts
    
        Cryptographic Chain Continuity Invariant [INV-ADT-01]
          Every audit record must contain the cryptographic hash of its immediate predecessor.
          Audit logs with broken hash linkages or missing sequence numbers are classified as evidence tampering.
    
        Strict Fail-Closed Transactional Boundary [INV-ADT-02]
          Privileged administrative actions must not commit if audit event logging fails or times out.
          Executing state-mutating actions without verified audit trail commitment is strictly prohibited.
    
        Seven-Year WORM Storage Mandate [INV-ADT-03]
          Audit archives must be stored with S3 Object Lock in Compliance Mode for at least 7 years.
          Disabling object lock or enabling mutable lifecycle overwrites violates corporate regulatory policy.
    
    ## Explicit Unknowns
    
    - Cryptographic hashing throughput overhead when batching 2,200 events/sec across multiple multi-threaded nodes (G-1).
    - Cloud KMS API rate limits during automated verification audits traversing 50 million historical hash chains (G-2).
    
    ## Traceability
    
    | Claim | Classification | Source | Freshness |
    |---|---|---|---|
    | 2,200 audit events/sec across 45 services | provided | Volumetric intake | Current |
    | Incident AUD-4819 insider log tampering | provided | Post-mortem incident record | Historical |
    | SEC Rule 17a-4 and PCI-DSS v4.0 Req 10 | provided | Regulatory compliance mandate | Current |
    | SHA-256 sequential hash chaining | decided | David O'Reilly (CISO SecOps) | 2026-09-15 |
    | S3 Object Lock Compliance Mode 7-year WORM | decided | Elena Rostova (Financial Compliance) | 2026-09-15 |
    | Fail-closed transactional boundary (< 500ms) | decided | Architectural invariant INV-ADT-02 | 2026-09-15 |
    
    
    ## Verification
    
    No validator was supplied, so no command was run.
    
    Reviewer self-check against security audit logging standards:
    - **Tamper Evidence**: PASS. Cryptographic hash chaining ensures any modified historical event breaks the chain.
    - **Fail-Closed Safety**: PASS. Privileged financial mutations abort if audit logging fails within 500 ms.
    - **WORM Immutability**: PASS. S3 Object Lock in Compliance Mode locks archives against deletion for 7 years.
    - **Markdown Hygiene**: PASS. Native Markdown syntax strictly adheres to `rule_markdown.md`.
    
    ## Open Decisions
    
    - `DEC-ADT-01`: David O'Reilly to determine whether daily Merkle root hashes should be published to a public timestamping ledger (e.g. RFC 3161 or Certificate Transparency) for external third-party proof (Owner: David O'Reilly).
    
    ## Next steps
    
    1. Marcus Vance provisions S3 audit vault bucket with Object Lock in Compliance Mode via Terraform.
    2. Platform team implements CADF structured logger and SHA-256 chaining middleware in core service libraries.
    3. Conduct staging resilience drill simulating audit sink failure to verify complete transaction rollback.
    

    security-audit-event-logging-contract-de.tsx

    TSX · React component

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Define immutable schemas for security-critical event loggingEstablish cryptographic tamper-evidence requirements for audit trailsMap accountability obligations to specific audit-record semanticsDesign retention and privacy-minimization rules for evidence logs

    About this skill

    What it does

    This skill maps accepted accountability/security obligations and authoritative business/security actions into audit-event, recording, protection and evidence contracts. It defines what an audit record means and how gaps/failures remain visible without selecting a logging stack.

    Use it when

    Use when known security/accountability events require exact audit-record semantics, protection, lifecycle and producer-failure behavior.

    For example: “Regulators asked us to prove who approved a EUR 2m payment last March. We have application logs but they rotate after 30 days and an admin can delete them.”

    What you get

    • Audit Logging Specification

    Written as Markdown to <your output folder>/architecture/tasks/<run-id>/audit-logging-design/.

    What it will not do

    Do not use for application/diagnostic logging, metrics/tracing, security-monitoring/SIEM architecture, domain-event or CDC design, legal/compliance interpretation, one logger implementation, forensic investigation or alerting.

    How it works

    1. Check the log must be evidence, not diagnostics.
    2. List the questions the log must answer, and to whom.
    3. Fix the event schema: actor, action, object, outcome, time.
    4. Make tampering detectable, not merely difficult.
    5. State retention and what may never be written.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-task.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions