Short answer
ISO 27001 Annex A control 8.15, Logging, requires logs that record activities, exceptions, faults and other relevant events to be produced, stored, protected and analysed. In practice that means a logging standard defining which events each system records, central collection, protection against tampering, defined retention, and evidence that logs are reviewed.
Key takeaways
- Define which events to log per system type.
- Collect logs centrally and protect them from changes and deletion.
- Set retention based on legal, contractual and investigation needs.
- Logs must be analysed, not just stored; A.8.16 covers monitoring.
What the control says
A.8.15 requires logs that record activities, exceptions, faults and other relevant events to be produced, stored, protected and analysed. ISO/IEC 27002 guidance lists typical events such as user IDs, system activities, dates and times, successful and rejected access attempts, configuration changes, use of privileges and system utilities, and activation of protection systems. It also covers protecting logs from tampering and protecting privileged users' activity logs from those users.
What to log
| Source | Events to capture |
|---|---|
| Identity provider | Sign-ins, failures, MFA changes, admin role changes |
| Servers and endpoints | Logons, privilege use, security tool alerts |
| Cloud platforms | API calls, configuration and permission changes |
| Applications | Access to sensitive data, admin actions, exports |
| Network and security tools | Firewall denies, WAF blocks, IDS alerts |
Protecting logs
- Send logs to a central system separate from the systems that create them.
- Restrict who can change or delete logs, including administrators of the source systems.
- Use time synchronisation so events line up ().
- Alert on logging failures, not just on security events.
Retention
ISO 27001 doesn't set a retention period. Base it on legal and contractual requirements and on how far back you'd need to investigate. Many organisations keep a short period searchable and a longer period archived. Write the decision down and apply it.
Analysis and review
Logs only help if someone or something looks at them. Automated alerting covers ; A.8.15 also expects analysis, such as periodic review of privileged activity and follow-up of anomalies. Keep records of reviews and of what was done about findings.
Evidence auditors sample
- Logging standard listing sources and events
- Central log platform showing those sources are connected
- Access controls on the log platform
- Retention settings matching the standard
- Review records or alert handling tickets
A.8.15LoggingSOC 2 CC7.2Monitoring for anomaliesA.8.15LoggingNIST CSF PR.PS-04Log records generatedA.8.15LoggingPCI DSS Req 10Log and monitor all access
Put this into practice on QULDEX
Frequently asked questions
How long should logs be kept for ISO 27001?
The standard doesn't set a period. Decide based on legal, contractual and investigation needs, and document it.
What is the difference between A.8.15 and A.8.16?
A.8.15 covers producing, storing, protecting and analysing logs. A.8.16 covers monitoring networks, systems and applications for anomalous behaviour and acting on it.