Skip to main content
Category: Logging and Monitoring

Event Logging

Also known as: Logging, Annex A 8.15, Control 8.15
Simply put

Event Logging is an ISO 27001 control that requires an organization to keep records of activities happening across its systems, such as user actions, errors, and unusual events. These logs must be produced, stored securely, protected from tampering, and reviewed so the organization can spot and investigate security problems. It is one of the reference controls listed in Annex A of the standard, selected based on an organization's risk assessment.

Formal definition

Control 8.15 (Logging) is a technological reference control in Annex A of ISO/IEC 27001:2022 that requires organizations to produce, store, protect, and analyze logs recording user activities, exceptions, faults, and other relevant security events. In most implementations, this involves generating event records suitable for security monitoring, incident investigation, and compliance evidence, while protecting log integrity and access against unauthorized modification. As an Annex A control, its inclusion and scope are determined through the Statement of Applicability and informed by risk assessment rather than being universally mandatory; detailed implementation guidance for this control is elaborated in the corresponding ISO/IEC 27002:2022 control. The control attests only to logging practices within the defined ISMS scope and does not, on its own, guarantee complete detection of all security events.

Why it matters

Event logging provides the evidentiary foundation for detecting, investigating, and understanding security incidents. Without reliable records of user activities, exceptions, faults, and other relevant events, an organization has limited ability to reconstruct what happened during a suspected compromise or to demonstrate that its controls were operating as intended. Logs support security monitoring, incident investigation, and compliance evidence, making Control 8.15 a practical enabler for several broader security objectives within an ISMS.

The value of logging depends heavily on the integrity and availability of the logs themselves. If records can be altered or deleted by an attacker or an insider, their evidentiary value collapses precisely when it is most needed. For this reason the control emphasizes not only producing logs but also storing them securely, protecting them from tampering, and reviewing them so that anomalies can be surfaced and acted upon. Logs that are generated but never analyzed offer little defensive benefit.

It is important to recognize the boundaries of this control. Logging attests only to logging practices within the defined ISMS scope and does not, on its own, guarantee complete detection of all security events. As an Annex A reference control, its inclusion and depth are determined through the Statement of Applicability and informed by risk assessment rather than being universally mandatory. Its effectiveness in any given engagement depends on scope, the systems covered, and how consistently review activities are carried out.

Who it's relevant to

Security Engineers and IT Operations
Those responsible for configuring systems typically implement the mechanisms that generate event records, ensure logs are stored securely, and protect them from unauthorized modification. They also often build or maintain the tooling used to review logs for anomalies and support incident investigations.
Incident Response Teams
Responders rely on event logs to reconstruct the sequence of activities during a suspected compromise. The completeness and integrity of logging directly affects how effectively they can investigate, though logging alone does not guarantee that all security events will be detected.
GRC and Compliance Managers
Compliance professionals determine whether Control 8.15 is applicable through the Statement of Applicability and risk assessment, and document its scope within the ISMS. They also treat logs as one form of compliance evidence, keeping in mind that the control attests only to logging practices within the defined ISMS scope.
ISO 27001 Auditors
Certification body auditors assess whether the organization's logging practices align with what is stated in the Statement of Applicability and whether logs are produced, protected, and analyzed as described. Their evaluation is scoped to the defined boundaries of the ISMS.

Inside Event Logging

Reference to ISO/IEC 27001:2022 Annex A
Event Logging is control 8.15 within the Annex A reference controls of the 2022 revision of ISO/IEC 27001. It sits among the 93 controls organized into four themes in that edition, and is selected for inclusion via the Statement of Applicability informed by risk assessment rather than being automatically mandatory.
Recording of events
The control concerns producing, keeping, and reviewing logs that record activities, exceptions, faults, and other relevant events. What specifically is logged typically depends on the organization's scope, risk assessment, and applicable requirements rather than a single fixed list.
Log content elements
Logs commonly capture information such as user or account identifiers, event timestamps, activity details, and success or failure indicators. The precise fields recorded vary by system and by the risks the organization is seeking to address.
Review and analysis
Event logging is not only about collection; it typically includes provisions for reviewing logged events so that anomalies or security-relevant activity can be identified. The frequency and method of review depend on scope and organizational context.
Relationship to other controls
Event Logging (8.15) is often applied alongside related Annex A controls addressing matters such as log protection and clock synchronization. Detailed implementation guidance for such controls is provided in ISO/IEC 27002 rather than in ISO/IEC 27001 itself.

Common questions

Answers to the questions practitioners most commonly ask about Event Logging.

Is Event Logging control 8.15 a mandatory requirement of ISO 27001 certification?
Not automatically. The certifiable requirements of ISO/IEC 27001 sit in clauses 4 through 10. Annex A controls, including logging (referenced as 8.15 in the 2022 revision), are reference controls selected through the Statement of Applicability and informed by the risk assessment. An organization typically includes logging where its risk assessment supports it, but it may justify exclusion in the Statement of Applicability. So while logging is very commonly applicable, it is not universally mandated by the standard in the way clauses 4 to 10 are.
Does implementing Event Logging under ISO 27001 8.15 also satisfy the SOC 2 logging expectations?
Not directly or automatically. SOC 2 is an attestation examination performed under the AICPA SSAE 18 standard and evaluates controls against the Trust Services Criteria, whereas ISO 27001 8.15 is an Annex A reference control assessed within an ISMS certification. Mapping between the two is possible but partial, and the evidence, scoping, and evaluation approach differ. Satisfying the ISO 27001 logging control does not automatically satisfy the relevant SOC 2 criteria, and vice versa; each framework assesses the control on its own terms and scope.
What kinds of events are typically logged to support control 8.15?
The specific events depend on scope and risk assessment, but organizations commonly log activities such as user access and authentication, privileged or administrative actions, changes to systems and configurations, and security-relevant exceptions or faults. The appropriate set is driven by what the risk assessment identifies as significant, so the coverage varies between organizations rather than following a single fixed list.
How long should event logs be retained?
The standard does not prescribe a single fixed retention period. Retention is typically determined by the organization based on its risk assessment, operational needs, contractual obligations, and any applicable legal or regulatory requirements. Because these factors vary by organization and jurisdiction, the appropriate period should be defined in policy and justified rather than assumed from a universal number.
How can logs themselves be protected from tampering or unauthorized access?
Protecting log integrity is generally addressed alongside logging, since logs that can be altered lose evidential value. In most implementations this involves restricting access to log data, protecting logs against modification or deletion, and controlling administrative privileges over logging systems. The specific safeguards depend on scope and risk, and are typically coordinated with related access control and privileged access measures.
What evidence typically demonstrates that Event Logging is operating effectively?
Evidence expectations depend on the assessment context. For an ISO 27001 certification audit, this may include logging policy, configuration of logging on in-scope systems, and records showing logs are generated, protected, and reviewed. Where logging is assessed within a SOC 2 examination, particularly a Type II that evaluates operating effectiveness over a defined review period, evidence typically spans that period rather than a single point in time. The exact evidence requested varies by auditor, certification body, and scope.

Common misconceptions

Implementing Event Logging (8.15) is mandatory for every ISO 27001-certified organization.
Annex A controls, including 8.15, are reference controls selected through the Statement of Applicability and informed by risk assessment. While event logging is relevant in most environments, its applicability and the extent of implementation are determined by scope and risk rather than being universally imposed by the standard.
Satisfying Event Logging under ISO 27001 automatically meets SOC 2 logging expectations.
Mapping between ISO 27001 Annex A controls and the SOC 2 Trust Services Criteria is possible but partial. SOC 2 logging-related activities are assessed against the Common Criteria under an AICPA SSAE 18 attestation examination, and satisfying one framework does not automatically satisfy the other.
The control specifies exactly which events and fields must be logged.
The control describes categories of relevant events and typical log content, but the specific events, retention, and detail are determined by the organization's risk assessment and scope. Detailed implementation guidance appears in ISO/IEC 27002, and requirements vary between engagements and certification bodies.

Best practices

Base logging scope and content decisions on your risk assessment and document them consistently in the Statement of Applicability, noting how 8.15 was considered.
Capture log elements that support later analysis, typically including identities, timestamps, activity details, and success or failure indicators, tailored to each system's risk profile.
Establish a defined process for reviewing logs so that anomalies and security-relevant events can be identified, with review frequency justified by scope and risk.
Coordinate event logging with related controls such as log protection and clock synchronization, and consult ISO/IEC 27002 for detailed implementation guidance rather than treating ISO/IEC 27001 as prescriptive.
Align logging practices with any overlapping SOC 2 needs where relevant, while recognizing that mapping between the frameworks is partial and each is assessed separately.
Retain evidence of both logging configuration and log review activity so that operating effectiveness can be demonstrated over a review period, as is typically expected in a SOC 2 Type II examination.