Regulated customers in the pharmaceutical and life science industry must prove to authorities, how they control documents related to system operation and maintenance and preserves the complete history of changes made to these documents.
Frome the FDAs 21 CFR Part 11 requirements 11.10 (e) and 11.10 (k), the following Acceptance Criteria for audit trails can be derived:
The logout by session expiration must be logged in the audit trail.
Failed login attempts must be logged in the audit trail.
The following events shall be logged in the audit trail
Administrative operations on system level, such as restore of backups.
Thank you for raising this Idea on the Cumulocity IoT portal. We can confirm that we will consider this request for a future release, in the meantime you might like to know that failed login attempts are already logged, logout as a result of session expiration and administrative operations are not yet logged.
Regards, Jane