\item\fail{} Verify that an audit log or similar allows for non-repudiation of key transactions.
\begin{result}
- Failed login attempts, password reset, login/logout... are not logged at all.
+ Failed login attempts, password reset, login/logout\ldots are not logged at all.
It's not possible to retreive the IP address from which a password reset has been issued.
Only potential requests are logged even before it's verified such an action exists.
\end{result}
Time information is not inserted into log messages.
The actual log files however are named after the current system date, this gives a precision of 24 hours.
\end{result}
-\end{enumerate}
\ No newline at end of file
+\end{enumerate}