Perversely, this is exactly the logging that you want to have in place in case of a breach.
You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”
Perversely, this is exactly the logging that you want to have in place in case of a breach.
You can then (factually) make the statement that ”we have no evidence any customer data was accessed.”
If you need to search on some of this data you should use blind indexes (Google blind index for more info).
As an excuse for why to not do the right thing I really hate "plausible deniability".
I'd certainly argue your inability to account for processing operations after having been breached through lacking knowledge of what was done due to a lack of logs was therefore a breach.
I don't live in the US but I've watched as plausible deniability had been deployed there at the very highest levels, with great success, for 4 years.
https://aws.amazon.com/blogs/storage/protecting-data-with-am...