Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

SIAS v1.0 · Domain 12 of 19

LOG: Logging, monitoring and alerting

Security-relevant activity on in-scope systems is recorded, protected and kept long enough to investigate. Signs of attack become alerts that a named person evaluates in time to act, and the applicant checks regularly that this still works.

About this domain

What this domain covers. Log coverage and content, log protection, time synchronization and retention, detection rules, alert routing and triage, and testing of monitoring. Incident handling after an alert is escalated is in the INC domain.

Proportionate monitoring. SIAS does not require a 24/7 security operations center or an outsourced monitoring service. It requires that alerts are defined, routed to named people, and triaged within stated maximum times, with a documented arrangement for high-priority alerts outside business hours (on-call paging, automatic containment or another method the applicant can show works). Where monitoring is outsourced, the applicant remains responsible for meeting these requirements and must hold the records that show it.

Terms used in this domain.

  • High-impact system: any in-scope identity provider, cloud control plane, internet-facing system, system that stores or processes Restricted or other sensitive data (see SIAS-DAT-01), security tool, code-hosting or CI/CD system, or backup system.
  • Test event: a benign event that SecurityInspect generates, or asks the applicant to generate, to check that logging and alerting work (for example a failed sign-in with a test account). Test events are listed in the rules of engagement (the assessment plan) and never change production data or weaken a control beyond the agreed test.

What the software evaluates and what needs human judgment. SecurityInspect's proprietary security-analysis software must reconcile log sources with the asset inventory, read logging, retention and immutability settings, generate test events and measure when they arrive and whether they raise alerts, parse log records for required fields and for secrets, and compute triage times from alert records. Analysts decide whether detection rules would actually catch the conditions they target, whether triage decisions were sound, whether out-of-hours arrangements are proportionate to the risk, and whether an integrity mechanism would reveal tampering. Automated results count toward a rating only after a technical tester confirms or rejects each result that affects it.

Controls in this domain

4 controls, 3 of them mandatory.

Controls in the LOG domain
ControlTitleMandatorySeverityApplies
SIAS-LOG-01Security event logging coverageYesHighAll scopes
SIAS-LOG-02Log protection, time synchronization and retentionYesMediumAll scopes
SIAS-LOG-03Security alerting and triageYesHighAll scopes (coverage proportionate to risk; SIAS does not require a 24/7 operations center)
SIAS-LOG-04Monitoring effectiveness testing and log reviewNoMediumAll scopes

SIAS-LOG-01 Security event logging coverage

Mandatory
Yes
Severity
High
Applies
All scopes
SecurityInspect Verified profiles
VP-APP, VP-CLD

Control objective

Security-relevant activity on in-scope systems is recorded in enough detail to detect misuse and to reconstruct what happened.

Testable requirement

  • The applicant must:
  • 1.log these event categories on in-scope systems, wherever the system can produce them: successful and failed authentication; MFA enrollment, removal and reset; account and permission changes; privileged actions and elevations; security configuration changes, including changes to logging itself; cloud control-plane activity in every account and region in use; administrative or bulk access to Restricted or other sensitive data where the system supports it; detections by security tools; denied connections at the boundary of internet-facing systems; and security events in in-scope applications (authentication, authorization failures and rejected input at the application's own checks);
  • 2.include in each record a timestamp with time zone or UTC offset, the source system, the actor (user or workload identity), the action, the target, the outcome and, where relevant, the source network address;
  • 3.send logs from every high-impact system, and from at least 90% of other in-scope assets, to a central log platform, arriving within 15 minutes of the event;
  • 4.keep a log-source inventory that maps in-scope assets to log sources and is reconciled with the asset inventory (SIAS-AST-01);
  • 5.keep secrets, full credentials and unmasked Restricted data (for example passwords, session tokens and full payment card numbers) out of log records.

Applicability and scope

All scopes. SecurityInspect Verified profiles: VP-APP (the named application and its hosting, including application security events); VP-CLD (control-plane and resource logs in the named cloud tenants or accounts).

Pass criteria

  • 1.Every high-impact system captures each applicable event category in requirement 1 that it can produce.
  • 2.Sampled records carry the fields in requirement 2.
  • 3.Every high-impact system, and at least 90% of other in-scope assets, send logs to the central platform.
  • 4.Every test event appeared on the central platform within 15 minutes with the required fields.
  • 5.Cloud control-plane logging is enabled in every account and region in use.
  • 6.No secrets or unmasked Restricted data were found in the sampled logs.
  • 7.The log-source inventory matches the asset inventory, and differences are explained.

Severity

High. The global escalation rules apply; for example, log records containing credentials or Restricted data that unauthenticated parties can reach are escalated to Critical.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(1)(ii)(D), §164.312(b)
PCI DSS v4.0.1
10.2
Trust Services Criteria
CC7.2
ISO/IEC 27001:2022
A.8.15
Theme (SecurityInspect wording)
recording security-relevant activity

SIAS-LOG-02 Log protection, time synchronization and retention

Mandatory
Yes
Severity
Medium
Applies
All scopes
SecurityInspect Verified profiles
VP-CLD

Control objective

Logs can be trusted in an investigation: they are protected from change and deletion, carry consistent times, and remain available long enough.

Testable requirement

  • The applicant must:
  • 1.limit read access to logs to people who need it, and limit the ability to delete logs, alter them or change logging configuration on the central platform to a small, named group that is separate from the administrators of the systems producing the logs;
  • 2.protect central logs against alteration and deletion with immutable or write-once storage, or with an integrity mechanism that reveals changes (for example hash chaining or signed digests), so that records are removed only by the retention process;
  • 3.keep central logs resilient to the failure of a single storage location (for example through replication or backup);
  • 4.synchronize the clocks of in-scope systems to designated time sources that are themselves synchronized to a trustworthy external reference, keeping servers, network devices and log platforms within 1 second and endpoints within 5 seconds of the designated source, and limit who can change time settings;
  • 5.retain logs for at least 12 months, with at least the most recent 90 days searchable without a restore, or longer where law or contract requires;
  • 6.record every change to logging and retention configuration.

Applicability and scope

All scopes. SecurityInspect Verified profile: VP-CLD (logs of the named cloud tenants or accounts, wherever they are stored).

Pass criteria

  • 1.Every alteration and deletion attempt by an unauthorized test account failed.
  • 2.An immutability or integrity mechanism is in place, and A5 validated it where it applies.
  • 3.The rights to delete, alter or reconfigure logs are held by a small, named group separate from source-system administrators, or a compensating control accepted under this control is in place.
  • 4.Sampled clock offsets are within the tolerances in requirement 4.
  • 5.Retention is configured for at least 12 months, records are available back to the earlier of 12 months or the date logging began, and the most recent 90 days are searchable without a restore.
  • 6.Changes to logging configuration are recorded.

Severity

Medium. The global escalation rules apply.

Informative framework mappings

HIPAA Security Rule
§164.312(b)
PCI DSS v4.0.1
10.3, 10.5, 10.6
Trust Services Criteria
CC7.2
ISO/IEC 27001:2022
A.8.15, A.8.17
Theme (SecurityInspect wording)
protecting, time-stamping and retaining logs

SIAS-LOG-03 Security alerting and triage

Mandatory
Yes
Severity
High
Applies
All scopes (coverage proportionate to risk; SIAS does not require a 24/7 operations center)
SecurityInspect Verified profiles
None

Control objective

Signs of attack, misuse or failing security controls become alerts that a named person evaluates in time to act.

Testable requirement

  • The applicant must:
  • 1.maintain documented detection rules for at least these conditions, wherever they apply to the scope: grant of a privileged role; MFA disabled, removed or reset for a privileged user; sign-ins showing signs of compromise (for example from an unusual location, or from known-malicious addresses); repeated failed sign-ins and password spraying; creation of long-lived access keys for privileged or non-human identities; break-glass account use; malware detected on an in-scope host; unusual bulk access to or export of Restricted data where the system logs it; new public exposure of an in-scope system; and failure of critical security controls, including logging stopped, a high-impact log source silent for more than 24 hours, and security tools disabled or failing;
  • 2.route each alert to a named responder or on-call rotation under a documented coverage schedule;
  • 3.triage alerts within these maximum times from generation: high-priority alerts within 24 hours, including outside business hours through on-call paging, automatic containment or another documented method; other alerts within 3 business days;
  • 4.record the triage outcome for each alert (for example benign, false positive, or escalated as an incident under SIAS-INC-01), with timestamps;
  • 5.where monitoring is outsourced, define alert handling and escalation to the applicant in the service agreement, and keep records of escalations (see SIAS-TPR-02).

Applicability and scope

All scopes (coverage proportionate to risk; SIAS does not require a 24/7 operations center). Not part of any SecurityInspect Verified profile.

Pass criteria

  • 1.A rule exists for every condition in requirement 1 that applies to the scope.
  • 2.Every A3 test event raised an alert.
  • 3.In the look-back period, at least 95% of high-priority alerts were triaged within 24 hours and none took longer than 72 hours, and at least 90% of other alerts were triaged within 3 business days.
  • 4.SecurityInspect's test alerts were triaged within the maximum times.
  • 5.Every alert in the look-back period has a recorded outcome.
  • 6.A4 found no period without a named responder for high-priority alerts.
  • 7.Where monitoring is outsourced, the agreement and escalation records meet requirement 5.

Severity

High. The global escalation rules apply; if testing or triage records reveal active compromise, that is a Critical finding.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(1)(ii)(D), §164.308(a)(5)(ii)(C)
PCI DSS v4.0.1
10.4, 10.7
Trust Services Criteria
CC7.2, CC7.3
ISO/IEC 27001:2022
A.5.25, A.8.16
Theme (SecurityInspect wording)
detecting and evaluating security events

SIAS-LOG-04 Monitoring effectiveness testing and log review

Mandatory
No
Severity
Medium
Applies
All scopes
SecurityInspect Verified profiles
None

Control objective

The applicant checks regularly that its logging and alerting still work as intended, and improves them when they do not.

Testable requirement

  • The applicant must:
  • 1.test each high-priority detection rule at least every 6 months with benign simulated events or replayed data, and record each result;
  • 2.review log-source health (silent sources, parsing errors, ingestion gaps) at least weekly and fix the gaps found;
  • 3.review manually, at least weekly, the logs of in-scope systems that automated alerting does not cover, and record each review;
  • 4.review false positives and missed detections at least every 3 months, tune rules accordingly, and record each rule change;
  • 5.after each security incident or significant near miss, record whether detection worked and update the rules (see SIAS-INC-03).

Applicability and scope

All scopes. Not part of any SecurityInspect Verified profile.

Pass criteria

  • 1.Every high-priority rule was tested within the last 6 months, and each failed test was followed by a fix and a successful retest.
  • 2.Health reviews took place with no gap longer than 14 days in the look-back period.
  • 3.Manual reviews of logs not covered by alerting took place at the required interval.
  • 4.False-positive and missed-detection reviews took place at the required interval, and rule changes are recorded.
  • 5.The A3 re-runs produced the expected alerts.
  • 6.Post-incident records address detection, where incidents occurred.

Severity

Medium. The global escalation rules apply.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(1)(ii)(D)
PCI DSS v4.0.1
10.4
Trust Services Criteria
CC4.1, CC7.2
ISO/IEC 27001:2022
A.8.16
Theme (SecurityInspect wording)
checking that monitoring actually works

Framework mappings in this domain

The mappings above are informative cross-references by identifier only. They don’t reproduce any framework’s text, and meeting a SIAS control doesn’t mean any framework requirement is met.

What framework mappings mean

SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.

How SIAS relates to other security frameworks

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.