Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.15

Logging: A Practical Implementation Guide

Generate, protect and retain useful records of security-relevant activity.

This control concerns producing, storing, protecting and analyzing logs that record events, exceptions, faults and other relevant activity.

Practical interpretation: More logs are not automatically better. Logging should answer defined detection, investigation, accountability and compliance questions with reliable time and context.

What should the control achieve?

  • Logging requirements are defined by system and risk.
  • Events contain sufficient identity, action and outcome context.
  • Logs are protected from alteration and loss.
  • Retention and review support operational needs.

Step-by-step implementation

1

Define use cases

Identify investigations, detections, access accountability, fraud and compliance needs.

2

Specify events and fields

Capture identity, timestamp, source, action, object, result and correlation identifiers.

3

Centralize appropriately

Forward critical logs to protected collection with buffering.

4

Protect integrity

Restrict deletion and administration, monitor gaps and separate duties.

5

Set retention

Balance investigation windows, law, cost and privacy.

6

Validate continuously

Test event generation, parsing, timestamps, field quality and coverage.

What this could look like in practice

Cloud, identity, endpoint and application logs feed a central platform. Critical sources alert if silent. Only a separate logging team can change retention or delete data.

ActivityPractical implementationEvidence
AuthenticationSuccess, failure and factor events include identity and source.Identity log
Application actionSensitive record export records actor and object.Audit event
Log pipelineSource silence triggers operational alert.Coverage alert
InvestigationAnalyst correlates events with synchronized time.Case timeline

Implementation evidence

  • Logging standard
  • Use-case mapping
  • Source inventory
  • Event schemas
  • Central collection
  • Access controls
  • Retention settings
  • Coverage tests

Useful metrics

  • Critical sources reporting
  • Parsing failures
  • Log gaps
  • Retention compliance

Common mistakes

  • Logging passwords or excessive personal data.
  • Collecting events without use cases.
  • Allowing system admins to erase audit evidence.
  • Ignoring application-level actions.
  • No alert when sources stop reporting.

Questions an auditor may ask

  • Which events are required and why?
  • How are logs protected?
  • Show detection of a logging gap.
  • How is retention determined?
Implementation test: Perform a sensitive transaction and confirm complete, accurate, protected and searchable events appear end to end.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.