What an auditor, or Sekit's evidence engine, asks for.
Logging and monitoring configuration
How the company collects and keeps activity logs from its systems, and how security alerts are generated and handled.
From the Sekit evidence catalog
In practice
Logging for an SME succeeds or fails on one distinction: are logs centralized and protected, or scattered across each system's local storage where an attacker with admin rights can delete them. What works: ship logs from servers, endpoints, network devices and key cloud services into one platform, write them somewhere ordinary admin accounts cannot alter, and define retention up front. Alert on silent sources; a log feed that stops without anyone noticing looks identical to a safe system until an incident proves otherwise. Auditors ask which systems are missing from the central log platform, and how you would know if a feed went dark.
Common gaps
Logs are collected centrally for the main servers, but several cloud services and network devices were never onboarded to the platform, leaving blind spots.
Retention periods are set to defaults from the vendor rather than the values the log protection policy requires, and nobody has checked.
Administrators can delete or modify logs on the systems they manage, so an insider or attacker with admin rights could erase evidence of misuse.
Questions your auditor will ask
Which systems send their logs to the central platform, and which do not?
The centralized logging policy names every in-scope system, and a recurring onboarding review closes the gap whenever a new source is missing.
Can an administrator delete or alter logs after the fact?
No, logs are written to storage that ordinary admin accounts cannot modify or delete, and retention periods are enforced automatically by the platform.
How would you know if a log source stopped sending data?
Log source health is monitored automatically and an alert fires the moment an expected source goes quiet, rather than being discovered during an investigation.
How long are security-relevant logs kept, and is that documented?
The log protection and retention policy sets a defined period per log category, checked on a recurring basis against what is stored on the platform.
Where regulation demands it
NIS2 art. 3.2 requires monitoring and logging as part of incident detection capability. ENS op.exp.8 specifically expects activity to be logged and retained for review.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.