The Purpose of Logging
Logs serve three purposes in ISO 27001:
1Detection — Identifying security events and incidents
2Investigation — Understanding what happened after an incident
3Evidence — Demonstrating that controls are operating
What to Log
Authentication Events
•Successful and failed login attempts
•Password changes and resets
•MFA enrollment and bypass events
•Account lockouts
Authorisation Events
•Access to sensitive data or systems
•Privilege escalation
•Permission changes
•Access denials
System Events
•Configuration changes
•Service start/stop events
•Backup success/failure
•System errors and crashes
Application Events
•Data exports or bulk downloads
•Administrative actions
•API access patterns
•Error conditions
Log Management
Retention
•Define retention periods based on business and legal requirements
•Minimum 90 days for security-relevant logs
•12 months or more for compliance purposes
•Ensure logs survive system rebuilds
Protection
•Logs should be tamper-evident (write-once storage or centralised SIEM)
•Separate log storage from source systems
•Restrict access to log data
•Include log integrity in your risk assessment
Review
•Automated alerting for critical events
•Regular review of authentication failures
•Periodic analysis of access patterns
•Incident correlation across log sources
Monitoring
What to Monitor Actively
•Failed authentication attempts (brute force detection)
•Administrative access outside business hours
•Large data transfers
•Changes to security configurations
•New user account creation
Tools
You don't need an enterprise SIEM to start. Options by maturity:
•Basic Cloud provider native logging (CloudTrail, Azure Activity Log)
•Intermediate Centralised log aggregation (ELK, Grafana Loki)
•Advanced SIEM with automated correlation and alerting
What Auditors Check
•Are logs enabled for critical systems?
•Is there a defined retention period?
•Are logs protected from tampering?
•Is there evidence of log review?
•Can you demonstrate alerting on security events?
•Are administrator activities logged?
Common Mistakes
•Logging everything but reviewing nothing
•Logs only on some systems (missing critical ones)
•No log retention policy
•Logs that are easily deletable by administrators
•No timestamps or inconsistent time synchronisation