# Logging and monitoring policy

Source: https://aestech.com.au/policy-templates/#logging-and-monitoring-policy
Markdown URL: https://aestech.com.au/policy-templates/logging-and-monitoring-policy.md

Use for ISO 27001 A.8.15, A.8.16, A.8.17, SOC 2 Security, and PCI DSS requirements 10 and 11.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how events on company systems are logged, retained, protected and monitored so that security events can be detected, investigated and used as evidence.

2. Scope
This policy applies to all production systems, cloud platforms, identity and access systems, network devices, applications, security tools and administrative activity. It applies to all employees, contractors and service accounts whose actions are recorded.

3. Policy statements
- Security relevant events must be logged, including authentication, authorisation changes, privileged actions, access to sensitive data, configuration changes and security tool alerts.
- Logs must include enough detail to answer who did what, when, from where and the outcome.
- Clocks across systems must be synchronised to a reliable time source.
- Logs must be protected against unauthorised access, modification and deletion.
- Logs must be retained for at least [12] months, with at least [3] months immediately available, or longer where regulation requires.
- Security alerts must be reviewed and triaged, and confirmed events must follow the incident response process.
- Monitoring must include alerting for suspicious activity such as repeated failed logins, privilege escalation and unusual data access.

4. Roles and responsibilities
- The [Security Lead] owns the logging and monitoring programme and defines required log sources.
- IT and system owners ensure their systems forward required logs.
- The [Security Operations] function or designated staff review and triage alerts.
- The [Incident Response] team handles confirmed security events.

5. Procedures
- Maintain a list of in-scope log sources and required event types.
- Forward logs to a central, access-controlled logging platform.
- Configure time synchronisation across systems.
- Define and tune alert rules for high-risk activity.
- Review alerts on a defined cadence and record actions taken.
- Periodically verify that critical log sources are still reporting.

6. Evidence and records
Keep the log source inventory, logging configuration, retention settings, alert rules, alert review records, time synchronisation configuration and access controls on the logging platform.

7. Review cadence
This policy is reviewed at least annually and after material changes to systems or threats.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md