Test · TST-SOC2-LOG-01
LOG-01 · Security events are centrally logged and monitored 24x7
PassQ3 2026 Unified Program ReviewTested 3 Oct 2026 by Laura Bennett · Kestrel Assurance LLP
Requirement to validation
Requirement
ISO-A.8.15 · ISO-A.8.16 · RBI-CSF-NBFC-Annex-1-2 · RBI-ITGRCA-2023-7.6 · SOC2-CC7.2 · SOC2-CC7.3
mapped
Policy
Logging & Security Monitoring Standard
pol-logging
Control
LOG-01
Security events are centrally logged and monitored 24x7
Application
Amazon Web Services (ap-south-1) · Microsoft Entra ID · Meridian Customer Portal
mapped
Evidence · Q3
4 items
3 approved · 1 pending · 0 rejected
Test · Q3
Pass
TST-SOC2-LOG-01 · High confidence
Finding
F-IAQ2-LOG-01 · Medium
Closed
Action
Ananya Rao
REM-F-IAQ2-LOG-01 · Closed
Validation
Validated
as recorded
Procedure and result
- Procedure
- Microsoft Sentinel with data connectors; SOC runbooks. Tests: Amazon Web Services (ap-south-1): CloudTrail organisation trail enabled; Microsoft Entra ID: Entra diagnostic logs streamed to SIEM; Meridian Customer Portal: Portal audit events received in last 24h. Frequency continuous.
- Sample
- 2 items sampled (reperformance)
- Expected
- Security logs from Entra ID, AWS CloudTrail, GitHub, SAP and the Customer Portal are centralised in the SIEM and high-severity alerts are triaged by the SOC within 30 minutes.
- Observed
- Operating effectiveness confirmed for AWS, Microsoft Entra ID, Meridian Customer Portal; no exceptions in 2 sample(s).
- Confidence
- High