ISO 27701:2019
PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

ISO 27701:2019 6.9.4: Logging and monitoring

Event logs must be reviewed by continuous automated monitoring or by manual review at a documented frequency to find irregularities and propose remediation, logs must where possible record access to personal data including who accessed it, when, whose data it was and what changes resulted, roles must be defined and agreed where several providers share the logging duty, log information that itself contains personal data must be access controlled so it is used only as intended and deleted or de-identified per the retention schedule, and a processor must define and publish to customers the criteria for making log information available while ensuring one customer can never read or amend another's records; protection of logs, administrator and operator logs and clock synchronization apply as the base guidance requires.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 143 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 26 controls

  • 10.2.1 10.2.1 Audit logging enabled on all system components
  • 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data
  • 10.2.1.2 10.2.1.2 Logs capture all administrative actions
  • 10.2.1.3 10.2.1.3 Access to the audit logs is itself logged
  • 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts
  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 10.2.2 10.2.2 Required details recorded for each auditable event
  • 10.3.1 10.3.1 Audit log read access limited to job need
  • 10.3.2 10.3.2 Audit log files protected from modification
  • 10.3.3 10.3.3 Audit logs promptly backed up to central secure storage
  • 10.3.4 10.3.4 File integrity monitoring on audit logs
  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 10.4.1.1 10.4.1.1 Automated mechanisms used for audit log review
  • 10.4.2 10.4.2 Periodic review of all other system component logs
  • 10.6.1 10.6.1 System clocks synchronized with time-sync technology
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 10.7.1 10.7.1 Service providers detect critical control failures (superseded)
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic
  • 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program
  • 5.3.4 5.3.4 Anti-malware audit logs enabled and retained
  • 8.2.7 8.2.7 Third-party remote access accounts controlled
  • 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.4.4 9.4.4 Management approval for media leaving facility
  • 9.4.5 9.4.5 Inventory logs of electronic media

NIST SP 800-53 Rev 5 · 22 controls

CIS Controls v8 · 12 controls

  • CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
  • CIS-1.5 Use a Passive Asset Discovery Tool
  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.2 Deploy a Host-Based Intrusion Detection Solution
  • CIS-13.6 Collect Network Traffic Flow Logs
  • CIS-3.14 Log Sensitive Data Access
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.12 Collect Service Provider Logs
  • CIS-8.2 Collect Audit Logs
  • CIS-8.5 Collect Detailed Audit Logs
  • CIS-8.8 Collect Command-Line Audit Logs

CMMC 2.0 · 9 controls

C5 (Germany) · 8 controls

  • C5-OPS-10 Logging and Monitoring - Concept
  • C5-OPS-11 Logging and Monitoring - Metadata Management Concept
  • C5-OPS-12 Logging and Monitoring - Access, Storage and Deletion
  • C5-OPS-13 Logging and Monitoring - Identification of Events
  • C5-OPS-14 Logging and Monitoring - Storage of the Logging Data
  • C5-OPS-15 Logging and Monitoring - Accountability
  • C5-OPS-16 Logging and Monitoring - Configuration
  • C5-PSS-04 Error handling and Logging Mechanisms
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-06 Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

FedRAMP High · 5 controls

  • AU-3 Content of Audit Records
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-9 Protection of Audit Information
  • SA-1 Policy and Procedures
  • SC-45 System Time Synchronization (SC-45)

FedRAMP Moderate · 5 controls

  • AU-3 Content of Audit Records
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-9 Protection of Audit Information
  • SA-1 Policy and Procedures
  • SC-45 System Time Synchronization (SC-45)

SOC 2 · 5 controls

  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-PI1.3 PI1.3 Controls over system processing
  • ASBv3-LT-6 Configure log storage retention
  • ASBv3-LT-7 Use approved time synchronization sources
  • LT-3 Enable logging for security investigation
  • LT-5 Centralize security log management and analysis

HIPAA Security Rule · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

ISO 27001:2022 · 3 controls

  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.17 Clock synchronization 

ISO 27002:2022 · 3 controls

  • 5.28 Collection of evidence
  • 8.15 Logging
  • 8.16 Monitoring activities

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-171 Rev 3 · 2 controls

  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components

API 1164 · 1 control

  • API1164-11 Logging and Monitoring
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AESCSF-SA-1 Logging and monitoring

BSI IT-Grundschutz · 1 control

  • OPS.1.1.5 Logging

ISO 19011:2018 · 1 control

  • 6.4.10 Conducting closing meeting

ISO 27017:2015 · 1 control

  • 12.4 Logging and monitoring

ISO 27018:2019 · 1 control

  • 12.4 Logging and monitoring

ISO/IEC 27011:2024 · 1 control

  • 27011-8.4 Logging and monitoring

ISO/IEC 27043:2015 · 1 control

  • ISO27043-24 Logging and monitoring

ISO/IEC 27400:2022 · 1 control

  • 27400-10.3 Logging and Monitoring

ISO/SAE 21434 · 1 control

  • ISO21434-24 Logging and monitoring

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 6.9.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 143 it maps to, and the evidence behind each claim, over MCP and REST.