Logging and monitoring questions in a vendor questionnaire
Four questions cover logging: what is logged, how you notice something wrong, how long logs are kept and whether anyone can alter them. Small teams answer them with the audit logs and alerts their providers already offer.
What the client wants to know
The client wants evidence that if something goes wrong with their data, you can find out who did what. They do not expect a security operations centre from a small vendor. They expect audit logs switched on in the main systems and someone who receives the alerts.
The 4 questions as clients phrase them
The kit covers 4 questions in this area. The wording varies between questionnaires, the control behind it does not.
- Do you log access to systems that hold our data?
- How do you detect suspicious activity?
- How long do you keep logs?
- Are logs protected against tampering?
What a good answer contains
- Logging: login and admin activity logs switched on in the email suite, code hosting and cloud accounts.
- Retention: at least 90 days.
- Detection: provider security alerts for suspicious logins and new admin grants, sent to a named contact, and logs checked when an alert fires.
- Tamper protection: logs held by the providers' logging features, which normal user accounts cannot change or delete.
Watch out for
Audit logging is often off by default. Check each main system before you answer yes. Do not claim 24/7 monitoring if no one is watching outside working hours.
Controls behind these answers
These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.
- Monitoring: Login and admin activity logs are switched on in the main systems and kept for at least 90 days. If not yet: Switch on audit logs in your email suite, code hosting and cloud accounts, and keep them for at least 90 days.
Example: how a prepared answer opens
Question: How do you detect suspicious activity?
Provider security alerts (suspicious logins, new admin grants, unusual activity) are switched on and go to [your security contact].
This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.
Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.