Test · TST-SOC2-LOG-01

LOG-01 · Security events are centrally logged and monitored 24x7

PassQ3 2026 Unified Program ReviewTested 3 Oct 2026 by Laura Bennett · Kestrel Assurance LLP

Requirement to validation

Procedure and result

Procedure
Microsoft Sentinel with data connectors; SOC runbooks. Tests: Amazon Web Services (ap-south-1): CloudTrail organisation trail enabled; Microsoft Entra ID: Entra diagnostic logs streamed to SIEM; Meridian Customer Portal: Portal audit events received in last 24h. Frequency continuous.
Sample
2 items sampled (reperformance)
Expected
Security logs from Entra ID, AWS CloudTrail, GitHub, SAP and the Customer Portal are centralised in the SIEM and high-severity alerts are triaged by the SOC within 30 minutes.
Observed
Operating effectiveness confirmed for AWS, Microsoft Entra ID, Meridian Customer Portal; no exceptions in 2 sample(s).
Confidence
High