Test · TST-Q2-LOG-01
LOG-01 · Security events are centrally logged and monitored 24x7
FailQ2 2026 Unified Program ReviewTested 18 Jun 2026 by Farah Khan, Vikram Mehta · Meridian Internal Audit
Requirement to validation
Requirement
ISO-A.8.15 · ISO-A.8.16 · RBI-CSF-NBFC-Annex-1-2 · RBI-ITGRCA-2023-7.6 · SOC2-CC7.2 · SOC2-CC7.3
mapped
Policy
Logging & Security Monitoring Standard
pol-logging
Control
LOG-01
Security events are centrally logged and monitored 24x7
Application
Amazon Web Services (ap-south-1) · Microsoft Entra ID · Meridian Customer Portal
mapped
Evidence · Q3
4 items
3 approved · 1 pending · 0 rejected
Test · Q3
Pass
TST-SOC2-LOG-01 · High confidence
Finding
F-IAQ2-LOG-01 · Medium
Closed
Action
Ananya Rao
REM-F-IAQ2-LOG-01 · Closed
Validation
Validated
as recorded
Procedure and result
- Procedure
- Microsoft Sentinel with data connectors; SOC runbooks. Tests: Amazon Web Services (ap-south-1): CloudTrail organisation trail enabled; Microsoft Entra ID: Entra diagnostic logs streamed to SIEM; Meridian Customer Portal: Portal audit events received in last 24h. Frequency continuous.
- Sample
- 25 items sampled (Q2 baseline)
- Expected
- Security logs from Entra ID, AWS CloudTrail, GitHub, SAP and the Customer Portal are centralised in the SIEM and high-severity alerts are triaged by the SOC within 30 minutes.
- Observed
- Authentication and payment-initiation events from the customer portal were not forwarded to the 24x7 SOC; coverage gap since the portal re-platforming in March.
- Confidence
- High