When designing for auditability, which THREE of the following pieces of information should be captured in security logs?
Essential for understanding the activity.
Why this answer
Who (user/service), what (action), and result (success/failure) are mandatory for reconstruction.