Skip to main content

Review product activity and access

DigiCert​​®​​ Trust Lifecycle Manager records administrative and certificate lifecycle activity in a tamper-evident audit log.

Capability

Detail

Coverage

Create, update, and delete actions across certificates, enrollments, profiles, seats, connectors, business units, agents, sensors, scans, and automation. Enrollment protocols log their own activity.

Integrity

Each record is stored with a corresponding hash. An integrity verification operation can confirm that a record hasn’t been altered.

Access

Access is controlled by the Logs permission.

Retention

Live audit records are retained for a configurable period, defaulting to 12 months, after which they’re moved to archive tables.

Your responsibilities

  1. Confirm the retention period meets your FedRAMP obligations. The default is 12 months. Adjust enterprise.audit-log-archival.retention-months if your authorization requires longer online retention.

  2. Export or forward audit records to your central log management or SIEM platform. Retention and correlation shouldn’t depend on the product's own retention window.

  3. Periodically run hash verification on a sample of records as evidence of integrity monitoring.

  4. Review privileged activity in a defined cadence. This includes key recovery, revocation, profile changes, connector changes, and business unit changes.

  5. Restrict the Logs permission to personnel with a genuine need.

Continuous compliance evidence

The deployment provides a machine-readable evidence endpoint that reports the current compliance state. The report includes FIPS mode, the active cryptographic provider, CMVP certificate details and version match, encryption-at-rest configuration, service availability, and data inventory reconciliation.

Use this endpoint as the authoritative source for continuous monitoring instead of copying static values into assessment documents.