SIAS-LOG-01 Security event logging coverage
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-APP, VP-CLD
Control objective
Security-relevant activity on in-scope systems is recorded in enough detail to detect misuse and to reconstruct what happened.
Testable requirement
- The applicant must:
- 1.log these event categories on in-scope systems, wherever the system can produce them: successful and failed authentication; MFA enrollment, removal and reset; account and permission changes; privileged actions and elevations; security configuration changes, including changes to logging itself; cloud control-plane activity in every account and region in use; administrative or bulk access to Restricted or other sensitive data where the system supports it; detections by security tools; denied connections at the boundary of internet-facing systems; and security events in in-scope applications (authentication, authorization failures and rejected input at the application's own checks);
- 2.include in each record a timestamp with time zone or UTC offset, the source system, the actor (user or workload identity), the action, the target, the outcome and, where relevant, the source network address;
- 3.send logs from every high-impact system, and from at least 90% of other in-scope assets, to a central log platform, arriving within 15 minutes of the event;
- 4.keep a log-source inventory that maps in-scope assets to log sources and is reconciled with the asset inventory (SIAS-AST-01);
- 5.keep secrets, full credentials and unmasked Restricted data (for example passwords, session tokens and full payment card numbers) out of log records.
Applicability and scope
All scopes. SecurityInspect Verified profiles: VP-APP (the named application and its hosting, including application security events); VP-CLD (control-plane and resource logs in the named cloud tenants or accounts).
Pass criteria
- 1.Every high-impact system captures each applicable event category in requirement 1 that it can produce.
- 2.Sampled records carry the fields in requirement 2.
- 3.Every high-impact system, and at least 90% of other in-scope assets, send logs to the central platform.
- 4.Every test event appeared on the central platform within 15 minutes with the required fields.
- 5.Cloud control-plane logging is enabled in every account and region in use.
- 6.No secrets or unmasked Restricted data were found in the sampled logs.
- 7.The log-source inventory matches the asset inventory, and differences are explained.
Severity
High. The global escalation rules apply; for example, log records containing credentials or Restricted data that unauthenticated parties can reach are escalated to Critical.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(1)(ii)(D), §164.312(b)
- PCI DSS v4.0.1
- 10.2
- Trust Services Criteria
- CC7.2
- ISO/IEC 27001:2022
- A.8.15
- Theme (SecurityInspect wording)
- recording security-relevant activity
SIAS-LOG-02 Log protection, time synchronization and retention
- Mandatory
- Yes
- Severity
- Medium
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-CLD
Control objective
Logs can be trusted in an investigation: they are protected from change and deletion, carry consistent times, and remain available long enough.
Testable requirement
- The applicant must:
- 1.limit read access to logs to people who need it, and limit the ability to delete logs, alter them or change logging configuration on the central platform to a small, named group that is separate from the administrators of the systems producing the logs;
- 2.protect central logs against alteration and deletion with immutable or write-once storage, or with an integrity mechanism that reveals changes (for example hash chaining or signed digests), so that records are removed only by the retention process;
- 3.keep central logs resilient to the failure of a single storage location (for example through replication or backup);
- 4.synchronize the clocks of in-scope systems to designated time sources that are themselves synchronized to a trustworthy external reference, keeping servers, network devices and log platforms within 1 second and endpoints within 5 seconds of the designated source, and limit who can change time settings;
- 5.retain logs for at least 12 months, with at least the most recent 90 days searchable without a restore, or longer where law or contract requires;
- 6.record every change to logging and retention configuration.
Applicability and scope
All scopes. SecurityInspect Verified profile: VP-CLD (logs of the named cloud tenants or accounts, wherever they are stored).
Pass criteria
- 1.Every alteration and deletion attempt by an unauthorized test account failed.
- 2.An immutability or integrity mechanism is in place, and A5 validated it where it applies.
- 3.The rights to delete, alter or reconfigure logs are held by a small, named group separate from source-system administrators, or a compensating control accepted under this control is in place.
- 4.Sampled clock offsets are within the tolerances in requirement 4.
- 5.Retention is configured for at least 12 months, records are available back to the earlier of 12 months or the date logging began, and the most recent 90 days are searchable without a restore.
- 6.Changes to logging configuration are recorded.
Severity
Medium. The global escalation rules apply.
Informative framework mappings
- HIPAA Security Rule
- §164.312(b)
- PCI DSS v4.0.1
- 10.3, 10.5, 10.6
- Trust Services Criteria
- CC7.2
- ISO/IEC 27001:2022
- A.8.15, A.8.17
- Theme (SecurityInspect wording)
- protecting, time-stamping and retaining logs
SIAS-LOG-03 Security alerting and triage
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes (coverage proportionate to risk; SIAS does not require a 24/7 operations center)
- SecurityInspect Verified profiles
- None
Control objective
Signs of attack, misuse or failing security controls become alerts that a named person evaluates in time to act.
Testable requirement
- The applicant must:
- 1.maintain documented detection rules for at least these conditions, wherever they apply to the scope: grant of a privileged role; MFA disabled, removed or reset for a privileged user; sign-ins showing signs of compromise (for example from an unusual location, or from known-malicious addresses); repeated failed sign-ins and password spraying; creation of long-lived access keys for privileged or non-human identities; break-glass account use; malware detected on an in-scope host; unusual bulk access to or export of Restricted data where the system logs it; new public exposure of an in-scope system; and failure of critical security controls, including logging stopped, a high-impact log source silent for more than 24 hours, and security tools disabled or failing;
- 2.route each alert to a named responder or on-call rotation under a documented coverage schedule;
- 3.triage alerts within these maximum times from generation: high-priority alerts within 24 hours, including outside business hours through on-call paging, automatic containment or another documented method; other alerts within 3 business days;
- 4.record the triage outcome for each alert (for example benign, false positive, or escalated as an incident under SIAS-INC-01), with timestamps;
- 5.where monitoring is outsourced, define alert handling and escalation to the applicant in the service agreement, and keep records of escalations (see SIAS-TPR-02).
Applicability and scope
All scopes (coverage proportionate to risk; SIAS does not require a 24/7 operations center). Not part of any SecurityInspect Verified profile.
Pass criteria
- 1.A rule exists for every condition in requirement 1 that applies to the scope.
- 2.Every A3 test event raised an alert.
- 3.In the look-back period, at least 95% of high-priority alerts were triaged within 24 hours and none took longer than 72 hours, and at least 90% of other alerts were triaged within 3 business days.
- 4.SecurityInspect's test alerts were triaged within the maximum times.
- 5.Every alert in the look-back period has a recorded outcome.
- 6.A4 found no period without a named responder for high-priority alerts.
- 7.Where monitoring is outsourced, the agreement and escalation records meet requirement 5.
Severity
High. The global escalation rules apply; if testing or triage records reveal active compromise, that is a Critical finding.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(1)(ii)(D), §164.308(a)(5)(ii)(C)
- PCI DSS v4.0.1
- 10.4, 10.7
- Trust Services Criteria
- CC7.2, CC7.3
- ISO/IEC 27001:2022
- A.5.25, A.8.16
- Theme (SecurityInspect wording)
- detecting and evaluating security events
SIAS-LOG-04 Monitoring effectiveness testing and log review
- Mandatory
- No
- Severity
- Medium
- Applies
- All scopes
- SecurityInspect Verified profiles
- None
Control objective
The applicant checks regularly that its logging and alerting still work as intended, and improves them when they do not.
Testable requirement
- The applicant must:
- 1.test each high-priority detection rule at least every 6 months with benign simulated events or replayed data, and record each result;
- 2.review log-source health (silent sources, parsing errors, ingestion gaps) at least weekly and fix the gaps found;
- 3.review manually, at least weekly, the logs of in-scope systems that automated alerting does not cover, and record each review;
- 4.review false positives and missed detections at least every 3 months, tune rules accordingly, and record each rule change;
- 5.after each security incident or significant near miss, record whether detection worked and update the rules (see SIAS-INC-03).
Applicability and scope
All scopes. Not part of any SecurityInspect Verified profile.
Pass criteria
- 1.Every high-priority rule was tested within the last 6 months, and each failed test was followed by a fix and a successful retest.
- 2.Health reviews took place with no gap longer than 14 days in the look-back period.
- 3.Manual reviews of logs not covered by alerting took place at the required interval.
- 4.False-positive and missed-detection reviews took place at the required interval, and rule changes are recorded.
- 5.The A3 re-runs produced the expected alerts.
- 6.Post-incident records address detection, where incidents occurred.
Severity
Medium. The global escalation rules apply.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(1)(ii)(D)
- PCI DSS v4.0.1
- 10.4
- Trust Services Criteria
- CC4.1, CC7.2
- ISO/IEC 27001:2022
- A.8.16
- Theme (SecurityInspect wording)
- checking that monitoring actually works