ISO 27001 Annex A 8.15 Audit Checklist

The ultimate audit guide to ISO 27001 Annex A 8.15 Logging

1. Log Generation Scope Alignment Verified

Verification Criteria: Event logs are generated for all security-relevant events including user access, privileged actions, system failures, and security alerts across the infrastructure.

Required Evidence: Configuration files or policy documents defining the specific event IDs and log levels (e.g., Information, Warning, Error) captured.

Pass/Fail Test: If critical systems (e.g., production databases or firewalls) are not generating logs for administrative login attempts, mark as Non-Compliant.

2. Log Attribute Completeness Confirmed

Verification Criteria: Each log entry contains sufficient detail to facilitate an investigation, including User ID, event type, date/time, success/failure status, and source/destination identifiers.

Required Evidence: Raw log samples from the SIEM or central log repository demonstrating the presence of all required metadata fields.

Pass/Fail Test: If log entries lack a unique identifier for the user or the specific system that generated the event, mark as Non-Compliant.

3. Centralised Log Repository Implementation Validated

Verification Criteria: Logs are transmitted from local assets to a centralised, dedicated log management system or SIEM in near real-time.

Required Evidence: Architecture diagram and data ingestion logs from the central repository (e.g., Splunk, Sentinel, ELK).

Pass/Fail Test: If security logs are only stored locally on the originating server with no off-site or centralised backup, mark as Non-Compliant.

ISO 27001 Toolkit Business Edition

4. Log Integrity and Protection Measures Verified

Verification Criteria: Logs are protected against unauthorised modification, deletion, or tampering through strict access controls and, where required, digital signatures or hashing.

Required Evidence: Access Control List (ACL) for the log repository and evidence that even system administrators cannot modify or delete historic log entries.

Pass/Fail Test: If a standard system administrator has the technical privilege to delete or alter audit logs within the central repository, mark as Non-Compliant.

5. Accurate Clock Synchronisation Confirmed

Verification Criteria: All systems involved in log generation utilize a synchronised time source to ensure accurate chronological correlation during incident response.

Required Evidence: NTP (Network Time Protocol) configuration settings across a sampled batch of servers, routers, and workstations.

Pass/Fail Test: If system clocks across the infrastructure differ by more than the policy-defined tolerance (e.g., 5 seconds), mark as Non-Compliant.

6. Privileged User Activity Monitoring Validated

Verification Criteria: Specific monitoring is active for accounts with elevated privileges, capturing every command or configuration change executed.

Required Evidence: SIEM dashboard filters or specific audit reports focused solely on “Superuser” or “Domain Admin” activities.

Pass/Fail Test: If the organisation cannot produce a filtered report of all actions taken by a specific administrator in the last 24 hours, mark as Non-Compliant.

7. Log Retention Period Compliance Verified

Verification Criteria: Logs are retained for a period that aligns with legal, regulatory, and business requirements as specified in the data retention schedule.

Required Evidence: Data retention settings within the SIEM or log storage tiers (e.g., Hot/Cold storage settings showing 365+ days).

Pass/Fail Test: If security logs are purged before the mandatory regulatory retention period (e.g., 6 months for certain jurisdictions) expires, mark as Non-Compliant.

8. Log Storage Capacity Management Confirmed

Verification Criteria: Adequate storage is allocated for logs to prevent data loss due to disk exhaustion or ingestion throttling.

Required Evidence: Monitoring alerts for log storage capacity and historic logs showing no “drops” or “gaps” during peak traffic periods.

Pass/Fail Test: If the logging system stopped recording events in the last 90 days due to a “Disk Full” condition, mark as Non-Compliant.

9. Continuous Log Review and Alerting Validated

Verification Criteria: Logs are actively reviewed, either manually or via automated correlation rules, to identify and alert on potential security incidents.

Required Evidence: List of active SIEM correlation rules and a history of alerts generated and triaged by the security team.

Pass/Fail Test: If logs are collected but never reviewed or used to trigger real-time security alerts, mark as Non-Compliant.

10. Log Handling Awareness and Training Verified

Verification Criteria: Personnel responsible for log management and review are appropriately trained and aware of their responsibilities regarding log integrity.

Required Evidence: Training records for SOC analysts and system administrators specific to log management tools and security analysis.

Pass/Fail Test: If the personnel tasked with reviewing logs cannot explain the criteria for escalating a log-based alert, mark as Non-Compliant.

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top