Security Answer Kit

All guides

Logging and monitoring questions in a vendor questionnaire

Four questions cover logging: what is logged, how you notice something wrong, how long logs are kept and whether anyone can alter them. Small teams answer them with the audit logs and alerts their providers already offer.

What the client wants to know

The client wants evidence that if something goes wrong with their data, you can find out who did what. They do not expect a security operations centre from a small vendor. They expect audit logs switched on in the main systems and someone who receives the alerts.

The 4 questions as clients phrase them

The kit covers 4 questions in this area. The wording varies between questionnaires, the control behind it does not.

  1. Do you log access to systems that hold our data?
  2. How do you detect suspicious activity?
  3. How long do you keep logs?
  4. Are logs protected against tampering?

What a good answer contains

Watch out for

Audit logging is often off by default. Check each main system before you answer yes. Do not claim 24/7 monitoring if no one is watching outside working hours.

Controls behind these answers

These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.

Example: how a prepared answer opens

Question: How do you detect suspicious activity?

Provider security alerts (suspicious logins, new admin grants, unusual activity) are switched on and go to [your security contact].

This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.

Back to all guides

Related: Vulnerability management Incident response

Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.