Event Logging
Event Logging is an ISO 27001 control that requires an organization to keep records of activities happening across its systems, such as user actions, errors, and unusual events. These logs must be produced, stored securely, protected from tampering, and reviewed so the organization can spot and investigate security problems. It is one of the reference controls listed in Annex A of the standard, selected based on an organization's risk assessment.
Control 8.15 (Logging) is a technological reference control in Annex A of ISO/IEC 27001:2022 that requires organizations to produce, store, protect, and analyze logs recording user activities, exceptions, faults, and other relevant security events. In most implementations, this involves generating event records suitable for security monitoring, incident investigation, and compliance evidence, while protecting log integrity and access against unauthorized modification. As an Annex A control, its inclusion and scope are determined through the Statement of Applicability and informed by risk assessment rather than being universally mandatory; detailed implementation guidance for this control is elaborated in the corresponding ISO/IEC 27002:2022 control. The control attests only to logging practices within the defined ISMS scope and does not, on its own, guarantee complete detection of all security events.
Why it matters
Event logging provides the evidentiary foundation for detecting, investigating, and understanding security incidents. Without reliable records of user activities, exceptions, faults, and other relevant events, an organization has limited ability to reconstruct what happened during a suspected compromise or to demonstrate that its controls were operating as intended. Logs support security monitoring, incident investigation, and compliance evidence, making Control 8.15 a practical enabler for several broader security objectives within an ISMS.
The value of logging depends heavily on the integrity and availability of the logs themselves. If records can be altered or deleted by an attacker or an insider, their evidentiary value collapses precisely when it is most needed. For this reason the control emphasizes not only producing logs but also storing them securely, protecting them from tampering, and reviewing them so that anomalies can be surfaced and acted upon. Logs that are generated but never analyzed offer little defensive benefit.
It is important to recognize the boundaries of this control. Logging attests only to logging practices within the defined ISMS scope and does not, on its own, guarantee complete detection of all security events. As an Annex A reference control, its inclusion and depth are determined through the Statement of Applicability and informed by risk assessment rather than being universally mandatory. Its effectiveness in any given engagement depends on scope, the systems covered, and how consistently review activities are carried out.
Who it's relevant to
Inside Event Logging
Common questions
Answers to the questions practitioners most commonly ask about Event Logging.