Skip to content
SecuriFii

Evidence

Logging that somebody actually reads

Most organisations collect far more than they review, and the audit question is about the review rather than the collection.

Facts checked2026-09-11

What do auditors expect from logging?

That security-relevant events are logged, that logs are protected from alteration including by the people they record, that they are retained long enough to investigate something discovered late, and that somebody or something examines them and acts.

The last is the gap. A log aggregator with no alerting satisfies collection and nothing else; an auditor asking for evidence of review will ask what was detected, when, and what happened next. A small number of tuned, actioned alerts is stronger evidence than terabytes nobody opens.

The bottom line

Be able to name something a log told you, and what you did about it. That is the evidence the control is alive.

Related insights