Control · LOG-02
Audit logs retained 180 days online and 5 years archived, tamper-protected
Logging & MonitoringSOC 2 · ISO 27001 · RBIRisk Medium
Requirement to validation
Requirement
ISO-A.8.15 · RBI-CSF-NBFC-Annex-1-2 · RBI-ITGRCA-2023-7.6 · SOC2-CC7.2
mapped
Policy
IT Governance Policy (RBI-aligned)
pol-itgov
Control
LOG-02
Audit logs retained 180 days online and 5 years archived, tamper-protected
Application
Amazon Web Services (ap-south-1) · SAP S/4HANA
mapped
Evidence · Q3
0 items
0 approved · 0 pending · 0 rejected
Test · Q3
Not tested
Finding
None
Action
None
Validation
Not planned
What should be true
System audit logs of critical applications are retained online for at least 180 days and archived for 5 years with immutability (object lock), in line with RBI audit-trail expectations.
- Requirements
- ISO-A.8.15 A.8.15 · LoggingRBI-CSF-NBFC-Annex-1-2 RBI-CSF-NBFC Annex 1 §2 · Cyber security — SOC monitoring, vulnerability management, incident reporting (RBI Cyber Security Framework for NBFCs (IT Framework for the NBFC Sector))RBI-ITGRCA-2023-7.6 RBI-ITGRCA-2023 §7.6 · Audit trails / logging — logs retained and reviewed; protected from tampering (RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023)SOC2-CC7.2 CC7.2 · Monitors system components for anomalies indicative of malicious acts
- Applications
- Amazon Web Services (ap-south-1)SAP S/4HANA
- Third parties
- —
- Testing procedure
- S3 Object Lock (compliance mode) on log archive; Sentinel retention 180 days. Tests: Amazon Web Services (ap-south-1): Log archive bucket has object lock and lifecycle; SAP S/4HANA: SAP Security Audit Log retention. Frequency monthly.
Findings (0)
○ No data available
Evidence (0)
○ No data available
Tests (0)
○ No data available