ISO/IEC 27001:2022 Annex A · Control 8.15
Logging: A Practical Implementation Guide
Generate, protect and retain useful records of security-relevant activity.
This control concerns producing, storing, protecting and analyzing logs that record events, exceptions, faults and other relevant activity.
What should the control achieve?
- Logging requirements are defined by system and risk.
- Events contain sufficient identity, action and outcome context.
- Logs are protected from alteration and loss.
- Retention and review support operational needs.
Step-by-step implementation
Define use cases
Identify investigations, detections, access accountability, fraud and compliance needs.
Specify events and fields
Capture identity, timestamp, source, action, object, result and correlation identifiers.
Centralize appropriately
Forward critical logs to protected collection with buffering.
Protect integrity
Restrict deletion and administration, monitor gaps and separate duties.
Set retention
Balance investigation windows, law, cost and privacy.
Validate continuously
Test event generation, parsing, timestamps, field quality and coverage.
What this could look like in practice
Cloud, identity, endpoint and application logs feed a central platform. Critical sources alert if silent. Only a separate logging team can change retention or delete data.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Authentication | Success, failure and factor events include identity and source. | Identity log |
| Application action | Sensitive record export records actor and object. | Audit event |
| Log pipeline | Source silence triggers operational alert. | Coverage alert |
| Investigation | Analyst correlates events with synchronized time. | Case timeline |
Implementation evidence
- Logging standard
- Use-case mapping
- Source inventory
- Event schemas
- Central collection
- Access controls
- Retention settings
- Coverage tests
Useful metrics
- Critical sources reporting
- Parsing failures
- Log gaps
- Retention compliance
Common mistakes
- Logging passwords or excessive personal data.
- Collecting events without use cases.
- Allowing system admins to erase audit evidence.
- Ignoring application-level actions.
- No alert when sources stop reporting.
Questions an auditor may ask
- Which events are required and why?
- How are logs protected?
- Show detection of a logging gap.
- How is retention determined?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.