Cybersecurity GRC 14 items
Logging, Monitoring & Detection Audit
Audits security logging, centralized monitoring, and detection capabilities to ensure events are captured, protected, and reviewed.
NIST 800-53ISO 27001:2022PCI DSS 4.0SOC 2
Free PDF · enter your email to download.
Log Generation & Coverage
- Are audit logs generated for security-relevant events across systems and applications? *
- Do logs capture user identity, event type, timestamp, source, and outcome? *
- Is all privileged and administrative activity logged? *
- Are logs generated for authentication successes and failures? *
Centralization & Time Synchronization
- Are logs aggregated to a centralized SIEM or log management platform? *
- Are system clocks synchronized to an authoritative time source? *
- Are logs protected from unauthorized modification or deletion? *
Retention
- Are audit logs retained for at least twelve months, with 90 days readily available? *
- Is the log retention period defined and enforced by policy? *
- What is the configured log retention period in days?
Review, Alerting & Detection
- Are logs reviewed regularly (automated or manual) for anomalies? *
- Are detection rules and alerts configured for suspicious or malicious activity? *
- Are alerts routed to responders with defined response procedures? *
- Are file integrity monitoring alerts generated for critical system files? *
Download the full Logging, Monitoring & Detection Audit checklist
Get it as a clean, printable PDF — free.
