LOGGING AND MONITORING POLICY
Legal name of the entity
Effective Date
Policy Owner Name or role (for example Security Operations)
Log retention for example 12 months Basis
ISO/IEC 27001 logging controls SOC 2 CC7 PCI DSS Req.10 This policy defines what activity is logged, how logs are protected and retained, and how the organisation monitors and reviews them to detect security events.
1. Purpose and scope
This policy applies across Legal name of the entity and is owned by Name or role (for example Security Operations) . Logs are retained for for example 12 months .
2. Controls
Logging and monitoring controls in place:
Control In place Centralised, protected log store No Access and authentication events logged No Logs protected from tampering No Alerting on suspicious activity No Regular log review No Clock synchronisation (NTP) No
3. Review and approval
Reviewed [cycle]; approved by Name and designation on [date].
Approved by
Name and designation
______________________
Policy Owner
Name or role (for example Security Operations)
______________________