Evidence
Logging that somebody actually reads
Most organisations collect far more than they review, and the audit question is about the review rather than the collection.
Facts checked — 2026-09-11
What do auditors expect from logging?
That security-relevant events are logged, that logs are protected from alteration including by the people they record, that they are retained long enough to investigate something discovered late, and that somebody or something examines them and acts.
The last is the gap. A log aggregator with no alerting satisfies collection and nothing else; an auditor asking for evidence of review will ask what was detected, when, and what happened next. A small number of tuned, actioned alerts is stronger evidence than terabytes nobody opens.
The bottom line
Be able to name something a log told you, and what you did about it. That is the evidence the control is alive.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.