Control · LOG-01
Security events are centrally logged and monitored 24x7
Logging & MonitoringSOC 2 · ISO 27001 · RBIRisk Medium
Requirement to validation
Requirement
ISO-A.8.15 · ISO-A.8.16 · RBI-CSF-NBFC-Annex-1-2 · RBI-ITGRCA-2023-7.6 · SOC2-CC7.2 · SOC2-CC7.3
mapped
Policy
Logging & Security Monitoring Standard
pol-logging
Control
LOG-01
Security events are centrally logged and monitored 24x7
Application
Amazon Web Services (ap-south-1) · Microsoft Entra ID · Meridian Customer Portal
mapped
Evidence · Q3
4 items
3 approved · 1 pending · 0 rejected
Test · Q3
Pass
TST-SOC2-LOG-01 · High confidence
Finding
F-IAQ2-LOG-01 · Medium
Closed
Action
Ananya Rao
REM-F-IAQ2-LOG-01 · Closed
Validation
Validated
as recorded
What should be true
Security logs from Entra ID, AWS CloudTrail, GitHub, SAP and the Customer Portal are centralised in the SIEM and high-severity alerts are triaged by the SOC within 30 minutes.
- Requirements
- ISO-A.8.15 A.8.15 · LoggingISO-A.8.16 A.8.16 · Monitoring activitiesRBI-CSF-NBFC-Annex-1-2 RBI-CSF-NBFC Annex 1 §2 · Cyber security — SOC monitoring, vulnerability management, incident reporting (RBI Cyber Security Framework for NBFCs (IT Framework for the NBFC Sector))RBI-ITGRCA-2023-7.6 RBI-ITGRCA-2023 §7.6 · Audit trails / logging — logs retained and reviewed; protected from tampering (RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023)SOC2-CC7.2 CC7.2 · Monitors system components for anomalies indicative of malicious actsSOC2-CC7.3 CC7.3 · Evaluates security events to determine whether they are incidents
- Third parties
- —
- Testing procedure
- Microsoft Sentinel with data connectors; SOC runbooks. Tests: Amazon Web Services (ap-south-1): CloudTrail organisation trail enabled; Microsoft Entra ID: Entra diagnostic logs streamed to SIEM; Meridian Customer Portal: Portal audit events received in last 24h. Frequency continuous.
Findings (1)
| Finding | Observation | Control | Applications | Severity | Status | Owner | Action | Validation |
|---|---|---|---|---|---|---|---|---|
| F-IAQ2-LOG-01 | Customer portal not onboarded to the SIEM | LOG-01 | Amazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer Portal | Medium | Closed | Ananya Rao | REM-F-IAQ2-LOG-01 · Closed | Validated |
Evidence (6)
| Evidence | Title | Control | Source system | Collected | Status |
|---|---|---|---|---|---|
| Q2-EV-024 | Amazon Web Services (ap-south-1) · ticket sample (Q2) | LOG-01 | Amazon Web Services (ap-south-1) | 3 Jun 2026 | Rejected |
| Q2-EV-025 | Microsoft Entra ID · access review (Q2) | LOG-01 | Microsoft Entra ID | 8 Jun 2026 | Rejected |
| RBI-REQ-018 | AWS: CloudTrail organisation trail enabled | LOG-01 | 7 Oct 2026 | Under review | |
| SOC2-REQ-028 | AWS: CloudTrail organisation trail enabled | LOG-01 | 5 Oct 2026 | Accepted | |
| SOC2-REQ-029 | Microsoft Entra ID: Entra diagnostic logs streamed to SIEM | LOG-01 | Microsoft Entra ID | 4 Oct 2026 | Accepted |
| SOC2-REQ-030 | Meridian Customer Portal: Portal audit events received in last 24h | LOG-01 | Meridian Customer Portal | 9 Oct 2026 | Accepted |
Tests (2)
| Test | Control | Cycle | Tested | By | Result | Confidence |
|---|---|---|---|---|---|---|
| TST-SOC2-LOG-01 | LOG-01 · Security events are centrally logged and monitored 24x7 | Q3 2026 Unified Program Review | 3 Oct 2026 | Laura Bennett · Kestrel Assurance LLP | Pass | High |
| TST-Q2-LOG-01 | LOG-01 · Security events are centrally logged and monitored 24x7 | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |