# Logging & Monitoring Policy

> **Template — adapt before use.** Replace `[bracketed]` placeholders and have an owner approve it. Not compliance advice.

| | |
|---|---|
| **Owner** | [Role] | **Approved** | [YYYY-MM-DD] | **Review** | Annual | **Version** | 1.0 |

Maps to: ISO 27001 A.8.15–8.16 · SOC 2 CC7.1–7.2 · PCI DSS Req 10 · HIPAA §164.312(b).

## 1. Purpose & scope
Defines what [Company Name] logs, how logs are protected and reviewed, and how security events are detected and escalated.

## 2. What is logged
- Authentication events (success/failure), privilege use, and access to sensitive data.
- Administrative actions and changes to security controls.
- System, application, and security-tool events sufficient to reconstruct an incident.
- Each entry includes: who, what, when, where (source), and outcome.

## 3. Protection & retention
- Logs are centralized, access-restricted, and protected from tampering.
- Retained for at least [12 months], with [3 months] readily available (align with PCI Req 10.5 where in scope).
- Clocks are synchronized via NTP.

## 4. Review & alerting
- Critical alerts are reviewed [daily / continuously]; defined alerts trigger escalation to the incident process.
- Periodic review of access to logs and of the logging coverage itself.

## 5. Evidence
Log samples, alert configurations, and review records are the audit evidence — retain them.

## Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | [YYYY-MM-DD] | [Name] | Initial issue |
