Logging
Logging is the practice of recording events and activities that happen within an organization's IT systems, such as user logins, file changes, or system errors, so they can be reviewed later. These records, called logs, help teams understand what happened, when, and who was involved. In a compliance context, logging provides the evidence that controls are actually operating over time.
Logging is the systematic capture, generation, and retention of timestamped records documenting events across systems, applications, network devices, and security tools (e.g., authentication attempts, configuration changes, access to sensitive data, and error conditions). In SOC 2 examinations, logging typically supports the Common Criteria (Security) and, depending on scope, other Trust Services Criteria, serving as evidence of the design and, in a Type II engagement, operating effectiveness of monitoring and access controls over the defined review period. Under ISO/IEC 27001, logging-related activities support ISMS requirements in clauses 4 through 10 and are commonly addressed through reference controls selected via the Statement of Applicability and informed by risk assessment (Annex A control counts and identifiers vary by edition, so the applicable version should be specified). The specific events logged, retention periods, and review cadence depend on scope, applicable criteria, the auditor or certification body, and organizational risk decisions rather than a single universal rule.
Why it matters
Logging is foundational to security compliance because it produces the durable, timestamped evidence that controls are actually functioning, not merely designed on paper. In a SOC 2 examination, particularly a Type II engagement that assesses operating effectiveness over a defined review period, logs are frequently the primary artifact an auditor relies on to confirm that monitoring, access, and change-management controls operated consistently throughout that period. Without reliable logs, an organization may be unable to demonstrate that a control worked on any given day, which can weaken the resulting report.
Beyond attestation and certification, logging matters because it enables detection and reconstruction of events. When an incident is suspected, logs allow teams to answer what happened, when it occurred, and who or what was involved. This investigative value is why logging typically supports the Common Criteria (Security) in SOC 2 and is commonly addressed among the reference controls an organization selects under an ISO/IEC 27001 ISMS. It is important to keep expectations realistic, however: the presence of logging does not by itself prevent breaches, and a SOC 2 report attests only to the controls and period covered while an ISO 27001 certificate covers only the defined scope of the ISMS.
The practical stakes are that gaps in logging, events not captured, logs not retained long enough, or reviews performed inconsistently, can surface as exceptions during an examination or nonconformities during a certification audit. Because the specific events logged, retention periods, and review cadence depend on scope, applicable criteria, and organizational risk decisions rather than a single universal rule, organizations should align their logging practices to the criteria and scope actually in play for their engagement.
Who it's relevant to
Inside Logging
Common questions
Answers to the questions practitioners most commonly ask about Logging.