Logging
Purpose
Produce, store, protect and analyse logs of activities, exceptions, faults and other relevant events.
How to meet this control
In short: Produce, store and protect logs of activities and events.
- Step 01Define a logging standard specifying which events to capture: authentication, privilege use, configuration changes, data access and errors
- Step 02Forward logs from endpoints, servers, cloud platforms and applications to a central SIEM or log platform such as Microsoft Sentinel, Splunk or an ELK stack
- Step 03Store logs in append-only or immutable storage so administrators cannot delete records of their own activity
- Step 04Synchronise clocks across all sources so events correlate accurately across systems
- Step 05Set a retention period that meets legal and investigation needs and protect logs with access controls
- Step 06Build correlation rules and dashboards so collected logs are actively analysed rather than just stored
Tip: Centralise logs; protect them from tampering and set retention.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Decide the purpose of logging, what to capture and how to protect it in a logging policy
- ›Capture details such as user IDs, activities, timestamps, device identity and network addresses
- ›Log access attempts, configuration changes, privilege use, file access and identity changes
- ›Synchronise time sources across systems so logs can be correlated
- ›Prevent users, including admins, from deleting or disabling logs of their own activity
- ›Protect logs with hashing and append-only or read-only storage
- ›Analyse logs to spot anomalies using SIEM, defined rules and threat intelligence
- ›Investigate suspected incidents through the incident management process
Audit evidence to keep
- - Logging policy listing event types captured and retention period
- - SIEM ingestion view showing logs from multiple source systems
- - Configuration proving logs are immutable or tamper-protected
- - Sample log entries with user ID, timestamp and source address
- - Evidence that clock synchronisation is enforced across sources
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.8.15. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.