ISO 27001

ISO 27001 A.8.15 Logging: what to log, how to protect it and how long to keep it

A.8.15 asks for logs that record activities, exceptions and faults, kept safe and analysed. Here is what to log, and what auditors check.

Short answer

ISO 27001 Annex A control 8.15, Logging, requires logs that record activities, exceptions, faults and other relevant events to be produced, stored, protected and analysed. In practice that means a logging standard defining which events each system records, central collection, protection against tampering, defined retention, and evidence that logs are reviewed.

Key takeaways

  • Define which events to log per system type.
  • Collect logs centrally and protect them from changes and deletion.
  • Set retention based on legal, contractual and investigation needs.
  • Logs must be analysed, not just stored; A.8.16 covers monitoring.

What the control says

A.8.15 requires logs that record activities, exceptions, faults and other relevant events to be produced, stored, protected and analysed. ISO/IEC 27002 guidance lists typical events such as user IDs, system activities, dates and times, successful and rejected access attempts, configuration changes, use of privileges and system utilities, and activation of protection systems. It also covers protecting logs from tampering and protecting privileged users' activity logs from those users.

What to log

SourceEvents to capture
Identity providerSign-ins, failures, MFA changes, admin role changes
Servers and endpointsLogons, privilege use, security tool alerts
Cloud platformsAPI calls, configuration and permission changes
ApplicationsAccess to sensitive data, admin actions, exports
Network and security toolsFirewall denies, WAF blocks, IDS alerts

Protecting logs

  • Send logs to a central system separate from the systems that create them.
  • Restrict who can change or delete logs, including administrators of the source systems.
  • Use time synchronisation so events line up ().
  • Alert on logging failures, not just on security events.

Retention

ISO 27001 doesn't set a retention period. Base it on legal and contractual requirements and on how far back you'd need to investigate. Many organisations keep a short period searchable and a longer period archived. Write the decision down and apply it.

Analysis and review

Logs only help if someone or something looks at them. Automated alerting covers ; A.8.15 also expects analysis, such as periodic review of privileged activity and follow-up of anomalies. Keep records of reviews and of what was done about findings.

Evidence auditors sample

  • Logging standard listing sources and events
  • Central log platform showing those sources are connected
  • Access controls on the log platform
  • Retention settings matching the standard
  • Review records or alert handling tickets
ISO 27001:2022Other frameworks
  1. A.8.15LoggingSOC 2 CC7.2Monitoring for anomalies
  2. A.8.15LoggingNIST CSF PR.PS-04Log records generated
  3. A.8.15LoggingPCI DSS Req 10Log and monitor all access
Full mappingPartial mappingIndicative mapping for planning.

Put this into practice on QULDEX

Frequently asked questions

How long should logs be kept for ISO 27001?

The standard doesn't set a period. Decide based on legal, contractual and investigation needs, and document it.

What is the difference between A.8.15 and A.8.16?

A.8.15 covers producing, storing, protecting and analysing logs. A.8.16 covers monitoring networks, systems and applications for anomalous behaviour and acting on it.

Sources

  1. ISO/IEC 27001:2022 Information security management systems: Requirements, ISO
  2. ISO/IEC 27002:2022 Information security controls, ISO
  3. NIST SP 800-92 Guide to Computer Security Log Management, NIST