The ultimate audit guide to ISO 27001 Annex A 8.15 Logging
Table of contents
- 1. Log Generation Scope Alignment Verified
- 2. Log Attribute Completeness Confirmed
- 3. Centralised Log Repository Implementation Validated
- 4. Log Integrity and Protection Measures Verified
- 5. Accurate Clock Synchronisation Confirmed
- 6. Privileged User Activity Monitoring Validated
- 7. Log Retention Period Compliance Verified
- 8. Log Storage Capacity Management Confirmed
- 9. Continuous Log Review and Alerting Validated
- 10. Log Handling Awareness and Training Verified
1. Log Generation Scope Alignment Verified
Verification Criteria: Event logs are generated for all security-relevant events including user access, privileged actions, system failures, and security alerts across the infrastructure.
Required Evidence: Configuration files or policy documents defining the specific event IDs and log levels (e.g., Information, Warning, Error) captured.
Pass/Fail Test: If critical systems (e.g., production databases or firewalls) are not generating logs for administrative login attempts, mark as Non-Compliant.
2. Log Attribute Completeness Confirmed
Verification Criteria: Each log entry contains sufficient detail to facilitate an investigation, including User ID, event type, date/time, success/failure status, and source/destination identifiers.
Required Evidence: Raw log samples from the SIEM or central log repository demonstrating the presence of all required metadata fields.
Pass/Fail Test: If log entries lack a unique identifier for the user or the specific system that generated the event, mark as Non-Compliant.
3. Centralised Log Repository Implementation Validated
Verification Criteria: Logs are transmitted from local assets to a centralised, dedicated log management system or SIEM in near real-time.
Required Evidence: Architecture diagram and data ingestion logs from the central repository (e.g., Splunk, Sentinel, ELK).
Pass/Fail Test: If security logs are only stored locally on the originating server with no off-site or centralised backup, mark as Non-Compliant.
DO IT YOURSELF
ISO 27001
All the templates, tools, support and knowledge you need to do it yourself.
4. Log Integrity and Protection Measures Verified
Verification Criteria: Logs are protected against unauthorised modification, deletion, or tampering through strict access controls and, where required, digital signatures or hashing.
Required Evidence: Access Control List (ACL) for the log repository and evidence that even system administrators cannot modify or delete historic log entries.
Pass/Fail Test: If a standard system administrator has the technical privilege to delete or alter audit logs within the central repository, mark as Non-Compliant.
5. Accurate Clock Synchronisation Confirmed
Verification Criteria: All systems involved in log generation utilize a synchronised time source to ensure accurate chronological correlation during incident response.
Required Evidence: NTP (Network Time Protocol) configuration settings across a sampled batch of servers, routers, and workstations.
Pass/Fail Test: If system clocks across the infrastructure differ by more than the policy-defined tolerance (e.g., 5 seconds), mark as Non-Compliant.
6. Privileged User Activity Monitoring Validated
Verification Criteria: Specific monitoring is active for accounts with elevated privileges, capturing every command or configuration change executed.
Required Evidence: SIEM dashboard filters or specific audit reports focused solely on “Superuser” or “Domain Admin” activities.
Pass/Fail Test: If the organisation cannot produce a filtered report of all actions taken by a specific administrator in the last 24 hours, mark as Non-Compliant.
7. Log Retention Period Compliance Verified
Verification Criteria: Logs are retained for a period that aligns with legal, regulatory, and business requirements as specified in the data retention schedule.
Required Evidence: Data retention settings within the SIEM or log storage tiers (e.g., Hot/Cold storage settings showing 365+ days).
Pass/Fail Test: If security logs are purged before the mandatory regulatory retention period (e.g., 6 months for certain jurisdictions) expires, mark as Non-Compliant.
8. Log Storage Capacity Management Confirmed
Verification Criteria: Adequate storage is allocated for logs to prevent data loss due to disk exhaustion or ingestion throttling.
Required Evidence: Monitoring alerts for log storage capacity and historic logs showing no “drops” or “gaps” during peak traffic periods.
Pass/Fail Test: If the logging system stopped recording events in the last 90 days due to a “Disk Full” condition, mark as Non-Compliant.
9. Continuous Log Review and Alerting Validated
Verification Criteria: Logs are actively reviewed, either manually or via automated correlation rules, to identify and alert on potential security incidents.
Required Evidence: List of active SIEM correlation rules and a history of alerts generated and triaged by the security team.
Pass/Fail Test: If logs are collected but never reviewed or used to trigger real-time security alerts, mark as Non-Compliant.
10. Log Handling Awareness and Training Verified
Verification Criteria: Personnel responsible for log management and review are appropriately trained and aware of their responsibilities regarding log integrity.
Required Evidence: Training records for SOC analysts and system administrators specific to log management tools and security analysis.
Pass/Fail Test: If the personnel tasked with reviewing logs cannot explain the criteria for escalating a log-based alert, mark as Non-Compliant.
