Test · TST-Q2-LOG-01

LOG-01 · Security events are centrally logged and monitored 24x7

FailQ2 2026 Unified Program ReviewTested 18 Jun 2026 by Farah Khan, Vikram Mehta · Meridian Internal Audit

Requirement to validation

Procedure and result

Procedure
Microsoft Sentinel with data connectors; SOC runbooks. Tests: Amazon Web Services (ap-south-1): CloudTrail organisation trail enabled; Microsoft Entra ID: Entra diagnostic logs streamed to SIEM; Meridian Customer Portal: Portal audit events received in last 24h. Frequency continuous.
Sample
25 items sampled (Q2 baseline)
Expected
Security logs from Entra ID, AWS CloudTrail, GitHub, SAP and the Customer Portal are centralised in the SIEM and high-severity alerts are triaged by the SOC within 30 minutes.
Observed
Authentication and payment-initiation events from the customer portal were not forwarded to the 24x7 SOC; coverage gap since the portal re-platforming in March.
Confidence
High