ISO 27001 Annex A 8.15 requires organisations to record security events, user activities, and exceptions. This is a documented process integrated into your existing business tools. You must store and protect these logs to prevent unauthorised changes. Local ownership ensures logs remain available for future security investigations.
Table of contents
Key Takeaways
- Record System and User Activities: Keep clear records of security events, staff actions, system errors, and exceptions across all company tools.
- Protect Log Integrity: Lock down log storage to stop staff, admins, or intruders from changing, editing, or deleting event records.
- Store Records Securely: Keep log files in safe central repositories so they stay available for security investigations and audits.
- Integrate Core Business Tools: Connect event logging directly into your standard operating systems, email tools, and cloud platforms.
- Review Logs Regularly: Monitor event logs routinely to spot suspicious user activities, policy breaks, or technical errors early.
- Define Log Retention Rules: Set clear timelines for how long to keep log records to meet business, ISO 27001, and legal requirements.
- Sync System Clocks: Ensure all servers and network devices use the exact same clock settings so log timestamps match across tools.
How to Implement ISO 27001 Annex A 8.15
- Write a Clear Logging Policy: Outline exact rules for capturing, storing, and protecting event records in standard internal docs.
- Identify Critical Systems: Map out all essential servers, databases, and apps that must generate activity logs.
- Set Up Automated Review Tasks: Use work tracking tools to trigger monthly reminders for IT teams to inspect log files.
- Document Log Review Results: Record all inspection outcomes, found errors, and cleanup steps in your team wiki.
- Restrict Access to Log Files: Use strict permission settings so only approved security staff can view log data.
- Set Clear Log Keep Times: Update record retention schedules to meet legal rules and business safety requirements.
- Report Log Alerts to Leaders: Review unusual log events and system warnings during monthly security committee meetings.
- Synchronise System Clocks: Align all system clocks to a shared time source so log timestamps match across all tools.
How to Audit ISO 27001 Annex A 8.15
- Check Logging Policies: Verify written rules for keeping records, setting keep times, and protecting private data are approved.
- Inspect Core Log Sources: Check key system and app logs to confirm tools capture main safety and admin actions.
- Verify Clock Sync: Check time settings on devices to ensure event timestamps match a single shared clock source.
- Test Log Protection: Try to edit or delete a test log entry to confirm protection rules stop file tampering.
- Review Monitoring Alerts: Check recent alert logs to confirm odd system actions trigger quick safety notices.
- Verify Storage Settings: Check storage space and archive rules to ensure files stay saved for required time frames.
- Inspect Admin Action Logs: Review admin activity logs to confirm privilege changes, rule edits, and user additions are tracked.
- Check Investigation Notes: Review recent safety alerts to confirm staff checked, logged, and solved issues instead of ignoring them.
- Interview System Admins: Ask IT staff how they set up logging tools to confirm daily steps follow written plans.
- Test Central Log Collection: Confirm log data from laptops, cloud tools, and network guards flows into one safe central folder.
- Verify Privacy Rules: Check log outputs to ensure automatic settings hide passwords and secret personal details from raw files.
- Document Audit Proof: Keep detailed records of log tests, setup screenshots, and check results to prove compliance.
- Check Log Backup Safety: Verify that extra log backups sit in a separate safe location to protect records against system failure.
- Confirm Incident Links: Check that system alert systems connect directly to clear action plans when security events occur.
Audit Evidence Checklist
- Logging and Retention Policy: Show a written log policy with a complete file history to prove periodic team updates and reviews.
- Log Review Work Tickets: Provide completed task tickets showing assigned and closed log review jobs.
- Management Meeting Minutes: Supply notes from leader meetings that show routine reviews of log errors and unusual activity.
- Storage Access Screenshots: Share screenshots of folder permission settings that prove log storage areas stay locked and protected.
- Internal Audit Reports: Present check reports that verify log file safety, record accuracy, and tool availability.
- Time Sync Screenshots: Provide configuration proof showing that all network devices and servers sync to a shared time source.
- Alert Investigation Notes: Maintain records of security warnings to show how staff checked and fixed flagged log events.
What to Teach Employees
- Understand Logging Purpose: Teach employees that system logging protects the company by recording key activities and detecting unauthorized access early.
- Recognize Logged Actions: Show workers which actions generate logs, including logins, file opens, rule changes, and software installs.
- Protect Log Credentials: Explain why sharing admin logins corrupts log records and creates serious safety risks.
- Report Log Tampering Alerts: Train IT staff to report warnings right away if logging tools stop running or files fail to sync.
- Maintain Accurate System Clocks: Remind technical staff never to change server clock settings by hand, as synced time sources are critical for security tracking.
- Avoid Logging Sensitive Data: Show developers and admins how to stop secret customer details or passwords from writing to app log files.
- Support Investigation Requests: Train staff to help security leads quickly when team members need log reviews during a safety check.
- Respect Log Privacy Standards: Ensure employees know that safety teams check activity logs only for security reasons under clear privacy rules.
- Lock Physical Log Access: Remind staff to keep paper activity logs and physical access records locked in safe office storage.
Common Implementation Challenges
- Automated Complacency: Caused by relying only on software green ticks without keeping actual test records. Fix this by adding regular log reviews to monthly meeting notes.
- Incomplete Logs: Caused by key computers and servers failing to send activity records to central storage. Fix this by updating your main system inventory to spot missing tools.
- No Retention Policy: Caused by deleting log files too early or keeping them forever without a plan. Fix this by publishing a clear schedule that sets exact record keep times.
- Log File Tampering: Caused by leaving log folders open so staff or intruders can change or delete file records. Fix this by locking storage permissions so only security tools can write log data.
- Alert Fatigue: Caused by logging too many normal daily events, which leads teams to miss real threats. Fix this by fine-tuning log rules to flag only high-risk system actions.
- Unmatched Timestamps: Caused by servers using different internal clocks, making it hard to track security events across tools. Fix this by syncing all system clocks to one shared time source.
How to Measure Effectiveness (KPIs)
- Log Coverage Rate: Measures the percentage of key servers, apps, and network devices actively sending event records to central storage.
- Mean Time to Detect: Tracks the average time needed for security tools or staff to spot unusual activity in system logs.
- Log Review Completion Rate: Measures the percentage of scheduled monthly log inspections completed and documented on time.
- Unchecked Alert Count: Counts open or unassigned log warnings to ensure security teams review and close every threat alert.
- Clock Sync Parity Rate: Tracks the percentage of system devices using the exact same central clock source for accurate event timestamps.
- Log Retention Compliance: Measures how well log storage meets required keep times without early file deletion or data loss.
- Failed Log Ingestion Rate: Tracks the frequency of network errors or server disconnections that prevent log files from saving properly.
- Unauthorized Access Attempts: Counts the number of times unapproved users try to edit, delete, or view protected log files.
Related ISO 27001 Controls
- ISO 27001 Annex A 8.16: Monitoring activities rely on accurate logs.
- ISO 27001 Annex A 5.24: Information security incident management needs log data.
- ISO 27001 Clause 9.1: Monitoring, measurement, analysis, and evaluation.


