GuideControls & Evidence

Logging & Monitoring: What to Capture and Why

Practical guidance on implementing logging and monitoring controls that provide real security value and audit evidence.

Updated 3 Mar 2026

The Purpose of Logging

Logs serve three purposes in ISO 27001:

1Detection — Identifying security events and incidents
2Investigation — Understanding what happened after an incident
3Evidence — Demonstrating that controls are operating

What to Log

Authentication Events

Successful and failed login attempts
Password changes and resets
MFA enrollment and bypass events
Account lockouts

Authorisation Events

Access to sensitive data or systems
Privilege escalation
Permission changes
Access denials

System Events

Configuration changes
Service start/stop events
Backup success/failure
System errors and crashes

Application Events

Data exports or bulk downloads
Administrative actions
API access patterns
Error conditions

Log Management

Retention

Define retention periods based on business and legal requirements
Minimum 90 days for security-relevant logs
12 months or more for compliance purposes
Ensure logs survive system rebuilds

Protection

Logs should be tamper-evident (write-once storage or centralised SIEM)
Separate log storage from source systems
Restrict access to log data
Include log integrity in your risk assessment

Review

Automated alerting for critical events
Regular review of authentication failures
Periodic analysis of access patterns
Incident correlation across log sources

Monitoring

What to Monitor Actively

Failed authentication attempts (brute force detection)
Administrative access outside business hours
Large data transfers
Changes to security configurations
New user account creation

Tools

You don't need an enterprise SIEM to start. Options by maturity:

Basic Cloud provider native logging (CloudTrail, Azure Activity Log)
Intermediate Centralised log aggregation (ELK, Grafana Loki)
Advanced SIEM with automated correlation and alerting

What Auditors Check

Are logs enabled for critical systems?
Is there a defined retention period?
Are logs protected from tampering?
Is there evidence of log review?
Can you demonstrate alerting on security events?
Are administrator activities logged?

Common Mistakes

Logging everything but reviewing nothing
Logs only on some systems (missing critical ones)
No log retention policy
Logs that are easily deletable by administrators
No timestamps or inconsistent time synchronisation

Related Modules

Standard Controls
Risk Register

Related Controls / Clauses

A.8.15
A.8.16
A.8.17

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.