Control · LOG-02

Audit logs retained 180 days online and 5 years archived, tamper-protected

Logging & MonitoringSOC 2 · ISO 27001 · RBIRisk Medium

Requirement to validation

What should be true

System audit logs of critical applications are retained online for at least 180 days and archived for 5 years with immutability (object lock), in line with RBI audit-trail expectations.

Requirements
ISO-A.8.15 A.8.15 · Logging
RBI-CSF-NBFC-Annex-1-2 RBI-CSF-NBFC Annex 1 §2 · Cyber security — SOC monitoring, vulnerability management, incident reporting (RBI Cyber Security Framework for NBFCs (IT Framework for the NBFC Sector))
RBI-ITGRCA-2023-7.6 RBI-ITGRCA-2023 §7.6 · Audit trails / logging — logs retained and reviewed; protected from tampering (RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023)
SOC2-CC7.2 CC7.2 · Monitors system components for anomalies indicative of malicious acts
Third parties
—
Testing procedure
S3 Object Lock (compliance mode) on log archive; Sentinel retention 180 days. Tests: Amazon Web Services (ap-south-1): Log archive bucket has object lock and lifecycle; SAP S/4HANA: SAP Security Audit Log retention. Frequency monthly.

Findings (0)

Open list →
○ No data available

Evidence (0)

Open list →
○ No data available

Tests (0)

Open list →
○ No data available