ISO 27018:2019
Operations security – ISO 27018:2019

ISO 27018:2019 12.4.1: Event logging

Extends ISO/IEC 27002:2013 12.4.1. Event logs are reviewed on a stated, documented cycle to spot irregularities and propose fixes. Where possible, logs show whether an event changed PII (added, modified or deleted it) and who made the change; where several providers in different service categories are involved, the roles in doing this may differ or be shared. The processor decides and writes down the conditions under which the customer may receive or use log information, including the timing and the method, and shares those procedures with the customer; a customer allowed to reach logs the processor controls sees only records of its own activities and nothing about other customers.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 7 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 1 control

FedRAMP Moderate · 1 control

ISO/IEC 27019:2024 · 1 control

  • ISO27019-12.4.1 Event Logging in Control Systems

NIST SP 800-171 · 1 control

PCI DSS 4.0 · 1 control

  • 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operations security – ISO 27018:2019

Query this from an agent

The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.