Security Questionnaire Mapper

Logging and monitoring: the clause the question tests

What is logged, how long it is kept and who watches it.

How the customer usually asks it

example

"Do you centrally log and monitor security events?"

Read this question

Anchor clauses

7 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20228.15 Logging · 8.16 Monitoring activities
SOC 2 (Trust Services Criteria)CC7.2 Monitors system components for anomalies indicating malicious acts
SIG (Shared Assessments)domain G IT Operations Management
NIST Cybersecurity Framework 2.0DE.CM-01 Networks and network services are monitored to find potentially adverse events
NIST SP 800-53 Rev 5AU-6 Audit record review, analysis, and reporting
PCI DSS v4.0.110.4.1 Daily log review for critical systems
HIPAA Security Rule (45 CFR 164)164.312(b) Audit Controls (Standard)

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The logging standard naming what is logged and for how long, the monitoring and alerting set-up, and a sample of the review record.

The clauses, with what an assessor asks for

ISO 27001 8.15 Logging

Produce, store, protect and analyse logs of activities, exceptions and faults.

Evidence an assessor expects: Log collection policy; Log storage and protection; Log review and analysis; Log retention and disposal
Where answers usually fall short: Inconsistent log collection across systems; Insufficient protection of log integrity
Source: ISO/IEC 27001:2022
ISO 27001 8.16 Monitoring activities

Monitor networks, systems and applications for anomalies and act on potential incidents.

Evidence an assessor expects: Network anomaly detection logs; System integrity monitoring reports; Application behavior alerts; Incident response records
Where answers usually fall short: Alerts not correlated across sources; Lack of documented response procedures for anomalies
Source: ISO/IEC 27001:2022
SOC 2 CC7.2 Monitors system components for anomalies indicating malicious acts

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The monitoring design for system components and their operation, showing what constitutes anomalous behaviour; Detection rules or analytics deployed, and evidence of the tuning applied over time; Evidence of the sources monitored, covering infrastructure, applications, identity and, where applicable, physical and environmental conditions; Records of anomalies detected during the period and of the analysis performed to determine whether they represent a security event; Evidence of the coverage of the monitoring against the components in the system description
Where answers usually fall short: Logs collected without any detection logic applied, so anomalies are only visible in hindsight; Monitoring covers malicious acts and omits natural disaster and error, both of which the criterion names
Source: SOC 2 (Trust Services Criteria)
SIG domain G IT Operations Management

What it asks for, in one line (the standard's own text is not quoted here):

Document and follow operational procedures for change management, capacity management, system hardening, backup, and operational monitoring for production systems.

Evidence an assessor expects: Operations procedure manual; Change advisory board minutes and tickets; Backup completion and restore test logs; Capacity reports
Where answers usually fall short: Backup restore not tested; Emergency changes routinely used to bypass CAB
Source: SIG (Shared Assessments)
NIST CSF DE.CM-01 Networks and network services are monitored to find potentially adverse events

Networks and network services are monitored to find potentially adverse events.

Evidence an assessor expects: Network flow telemetry coverage map by segment; IDS or NDR sensor inventory with placement diagram; DNS query analytics pipeline configuration; East-west traffic monitoring sample alerts; Egress monitoring policy and exception register
Where answers usually fall short: Encrypted traffic not inspected at chokepoints; Container and service mesh traffic invisible
Source: NIST Cybersecurity Framework 2.0
SP 800-53 AU-6 Audit record review, analysis, and reporting

Requires audit records to be reviewed and analysed on a defined frequency for indications of organization-defined inappropriate or unusual activity and its likely impact, findings to be reported to defined personnel, and the depth of review to be increased when credible information changes the risk.

Evidence an assessor expects: Defined review frequency and the activity indicators being looked for; Completed review records with reviewer, date and findings; Reports issued to the defined recipients and evidence of follow-up; Record of a review level adjustment made in response to changed risk
Where answers usually fall short: Review is automated alerting only, with no periodic analytical review for slow patterns; Findings recorded but never reported to anyone able to act
Source: NIST SP 800-53 Rev 5
PCI DSS 10.4.1 Daily log review for critical systems

What it asks for, in one line (the standard's own text is not quoted here):

The following audit logs are reviewed at least daily: all security events, logs of all CDE system components, logs of critical systems, and logs of authentication, authorization, and accounting services.

Evidence an assessor expects: SIEM dashboard showing daily review sign-off; Documented use cases reviewed daily; Triage tickets from daily reviews; Reviewer assignment and rotation; Sample of recent daily review records
Where answers usually fall short: Reviews skipped on weekends; No sign-off
Source: PCI DSS v4.0.1
HIPAA 164.312(b) Audit Controls (Standard)

Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. NIST recommends central log management aligned to SP 800-92.

Evidence an assessor expects: Logging standard; Central log management deployment; Log retention configuration; SIEM use case catalog
Where answers usually fall short: Application-level audit logs missing; Logs retained less than six years where applicable
Source: HIPAA Security Rule (45 CFR 164)

Other families in operations, logging and vulnerability