Logging and monitoring: the clause the question tests
What is logged, how long it is kept and who watches it.
How the customer usually asks it
example"Do you centrally log and monitor security events?"
Anchor clauses
7 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 8.15 Logging · 8.16 Monitoring activities |
| SOC 2 (Trust Services Criteria) | CC7.2 Monitors system components for anomalies indicating malicious acts |
| SIG (Shared Assessments) | domain G IT Operations Management |
| NIST Cybersecurity Framework 2.0 | DE.CM-01 Networks and network services are monitored to find potentially adverse events |
| NIST SP 800-53 Rev 5 | AU-6 Audit record review, analysis, and reporting |
| PCI DSS v4.0.1 | 10.4.1 Daily log review for critical systems |
| HIPAA Security Rule (45 CFR 164) | 164.312(b) Audit Controls (Standard) |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The logging standard naming what is logged and for how long, the monitoring and alerting set-up, and a sample of the review record.
The clauses, with what an assessor asks for
ISO 27001 8.15 LoggingProduce, store, protect and analyse logs of activities, exceptions and faults.
Where answers usually fall short: Inconsistent log collection across systems; Insufficient protection of log integrity
Source: ISO/IEC 27001:2022
ISO 27001 8.16 Monitoring activitiesMonitor networks, systems and applications for anomalies and act on potential incidents.
Where answers usually fall short: Alerts not correlated across sources; Lack of documented response procedures for anomalies
Source: ISO/IEC 27001:2022
SOC 2 CC7.2 Monitors system components for anomalies indicating malicious actsNamed, not quoted: the criteria text is not held in full here.
Where answers usually fall short: Logs collected without any detection logic applied, so anomalies are only visible in hindsight; Monitoring covers malicious acts and omits natural disaster and error, both of which the criterion names
Source: SOC 2 (Trust Services Criteria)
SIG domain G IT Operations ManagementWhat it asks for, in one line (the standard's own text is not quoted here):
Document and follow operational procedures for change management, capacity management, system hardening, backup, and operational monitoring for production systems.
Where answers usually fall short: Backup restore not tested; Emergency changes routinely used to bypass CAB
Source: SIG (Shared Assessments)
NIST CSF DE.CM-01 Networks and network services are monitored to find potentially adverse eventsNetworks and network services are monitored to find potentially adverse events.
Where answers usually fall short: Encrypted traffic not inspected at chokepoints; Container and service mesh traffic invisible
Source: NIST Cybersecurity Framework 2.0
SP 800-53 AU-6 Audit record review, analysis, and reportingRequires audit records to be reviewed and analysed on a defined frequency for indications of organization-defined inappropriate or unusual activity and its likely impact, findings to be reported to defined personnel, and the depth of review to be increased when credible information changes the risk.
Where answers usually fall short: Review is automated alerting only, with no periodic analytical review for slow patterns; Findings recorded but never reported to anyone able to act
Source: NIST SP 800-53 Rev 5
PCI DSS 10.4.1 Daily log review for critical systemsWhat it asks for, in one line (the standard's own text is not quoted here):
The following audit logs are reviewed at least daily: all security events, logs of all CDE system components, logs of critical systems, and logs of authentication, authorization, and accounting services.
Where answers usually fall short: Reviews skipped on weekends; No sign-off
Source: PCI DSS v4.0.1
HIPAA 164.312(b) Audit Controls (Standard)Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. NIST recommends central log management aligned to SP 800-92.
Where answers usually fall short: Application-level audit logs missing; Logs retained less than six years where applicable
Source: HIPAA Security Rule (45 CFR 164)