HLD Group
Logging & monitoring policy
Security logging, SIEM, and alerting requirements.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy defines what HLD Group logs, how logs are protected and retained, and how they are monitored to detect and respond to security events. Comprehensive, tamper-resistant logging is essential for detection, investigation, accountability, and compliance.
2. Scope
This policy applies to all production and security-relevant systems, applications, and services operated by HLD Group, and to the logging and monitoring infrastructure itself.
3. Definitions
- Audit log — a record of security-relevant events attributable to an identity
- SIEM — security information and event management platform that aggregates and correlates logs
- Log integrity — assurance that logs have not been altered or deleted
- Alert — a notification generated when monitoring detects a condition of interest
- Time synchronisation — consistent clocks across systems so events can be correlated
4. Events that must be logged
- Authentication successes and failures, and privilege escalation
- Access to sensitive and customer data
- Administrative and configuration changes to systems and security controls
- Creation, modification, and deletion of accounts and access rights
- Security control events — alerts, blocks, and detections
- Application errors and events relevant to security and integrity
5. Log content and quality
- Each event records who, what, when, where, and the outcome
- Timestamps use a synchronised, authoritative time source in a consistent timezone (UTC)
- Sensitive data and secrets are not written to logs; where unavoidable, they are masked
- Logs are structured to support automated correlation and search
6. Log protection and retention
- Logs are centralised promptly to a protected store separated from the systems that generate them
- Log integrity is protected against tampering and unauthorised deletion, with restricted, audited access
- Security logs are retained for at least 12 months, with the most recent 90 days readily searchable, and longer where a contract, legal hold, or regulation requires
- Retention aligns with the Data Retention Policy and legal hold requirements
7. Monitoring, alerting, and response
- Logs are correlated and analysed continuously, with automated detection for high-risk conditions
- Alerts are tuned to be actionable and are triaged within defined timeframes
- Detections feed directly into the Incident Response Policy
- Detection coverage is reviewed against known techniques and updated as threats evolve
8. Framework alignment
- ISO/IEC 27001:2022 Annex A controls 8.15 (logging), 8.16 (monitoring activities), and 8.17 (clock synchronisation)
- NIST SP 800-53 Rev. 5 control family AU (Audit and Accountability)
- SOC 2 Trust Services Criteria CC7.2 and CC7.3
- PCI DSS v4.0 Requirement 10 where cardholder data is in scope
9. Roles, exceptions, and review
Logging and monitoring are owned by the security function under the CISO. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually and after any incident in which detection or evidence proved inadequate.
Related frameworks
For contractual attestations or audit packs, contact [email protected].