A.8.15
    Technological Controls

    Logging

    Logs that record activities, exceptions, faults and other relevant events should be produced, stored, protected and analyzed.

    Purpose

    To record events and generate evidence for investigation and monitoring.

    Implementation Guidance

    Enable logging on all critical systems

    Centralize log collection and storage

    Protect logs from tampering and unauthorized access

    Define log retention periods

    Review logs regularly for security events

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.15 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.15 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.15 Logging. Built for compliance professionals.

    Try ISMS Copilot free