A8.15 Logging
4 min read
ISO 27001 A8.15 Logging emphasizes the need to establish, manage, and protect logs that support the detection of activities affecting information security. Logs should be sufficient to facilitate forensic investigations, detect patterns of misuse, and ensure traceability of user and system actions.
Logging is the process of recording events, actions, and operations within an IT environment. Proper logging is critical for monitoring, detecting anomalies, supporting investigations, and ensuring accountability. It helps organizations identify unauthorized access, trace operational issues, and maintain compliance with legal, regulatory, and security requirements.
Implementation Guide #
Step 1: Identify Logging Requirements
- Determine which systems and activities need to be logged—user access, system events, admin actions, security alerts, and application usage.
- Ensure compliance with regulatory requirements (e.g., GDPR, HIPAA, SOX).
→ Tool Recommendation: Elastic Stack (ELK), Graylog, Fluentd
Step 2: Enable and Configure Logging on Systems and Devices
- Enable logging for operating systems, applications, databases, firewalls, antivirus systems, and IDS/IPS.
- Configure log verbosity to balance security visibility and storage management.
→ Tool Recommendation:
– Windows Event Viewer, Linux syslog
– NGINX/Apache Logs, MySQL General Log, Fortinet/Firewall Logs
Step 3: Centralize Log Collection and Storage
- Use centralized logging platforms for aggregation, searchability, and long-term retention.
- Ensure logs are time-synchronized using NTP.
→ Tool Recommendation:
– SIEM Platforms: Splunk, IBM QRadar, LogRhythm, Microsoft Sentinel
– Open-source Tools: ELK Stack, Wazuh, OSSEC
Step 4: Secure and Protect Log Data
- Encrypt logs in transit and at rest.
- Implement access controls to prevent unauthorized log modification or deletion.
- Use tamper-evident mechanisms or write-once storage.
→ Tool Recommendation: Immutable storage options (e.g., AWS S3 Object Lock), HashiCorp Vault for key management
Step 5: Monitor Logs and Set Up Alerts
- Regularly review logs for suspicious activity, anomalies, or policy violations.
- Automate alerting for key events (e.g., failed logins, privilege escalation, access to sensitive data).
→ Tool Recommendation: Splunk Alerts, Datadog, Sentry, AlienVault OSSIM
Step 6: Define Retention and Archiving Policies
- Set log retention periods based on risk, legal, and operational needs.
- Implement log rotation and secure archiving practices.
→ Tool Recommendation: Logrotate, AWS Glacier, Azure Archive Storage
Step 7: Audit and Test Logging Effectiveness
- Regularly audit logs for completeness, integrity, and relevance.
- Test the logging process by simulating security events and verifying the logs capture them.
Templates #
- Logging and Monitoring Policy
- System Log Configuration Checklist
- Log Review and Audit Trail Template
- Incident Response Log Correlation Sheet
- Log Retention Schedule and Archive Policy
Example #
A financial organization implemented centralized logging using the ELK Stack and configured alerting via Wazuh to monitor administrator actions and access to financial records. When unusual login behavior was detected after hours, an alert was triggered, and the security team investigated and blocked an attempted breach.
Without effective logging, this behavior would have gone unnoticed until significant damage occurred.
How to Comply #
To comply with ISO 27001 A.8.15, organizations should:
- Enable and configure logging across critical systems and applications.
- Centralize log collection for visibility and correlation.
- Protect logs from tampering or unauthorized access.
- Establish clear retention policies and automate log archiving.
- Monitor logs continuously and set up alerting for high-risk events.
How to Pass an Audit #
Key Documents to Prepare:
- Logging and Monitoring Policy
- System and Application Log Configuration Settings
- Log Retention and Archiving Procedures
- Access Control Logs for Logging Systems
- Sample Log Review Reports and Incident Investigations
What the Auditor Will Check:
- Are appropriate systems and activities logged?
- Are logs reviewed regularly and alerts configured?
- Are logs secured and protected from modification?
- Are retention and disposal of logs documented and aligned with policy?
Top 3 Mistakes People Make #
- Logging too much or too little, leading to ineffective monitoring or excessive noise.
- Not securing or encrypting logs, risking integrity and confidentiality.
- Failing to review or act on logs regularly, reducing their operational and forensic value.
ISO 27001 Logging FAQ #
Q1: Should logs be collected in real-time?
Yes, especially for security-critical systems. Real-time log collection enables immediate detection and response to incidents.
Q2: How long should logs be retained?
This depends on compliance, business, and legal needs—commonly from 90 days to several years.
Q3: Can logging impact system performance?
Yes, if not optimized. Use buffering and offloading to centralized servers to minimize local performance issues.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.8.15 Logging | Detective, Technical, Risk-Based |
| Purpose | Ensure traceability of user and system activities to detect and investigate security incidents. |
| Applicability | All environments handling or processing sensitive or regulated information |
| ISO 27001 Domains | Operations Security, Monitoring and Logging, Information Security Incident Management |
By implementing effective logging practices, organizations gain visibility into their digital environments, detect issues early, and respond to threats before they escalate.