Metaluxo
← Insights

GRC

Logging and Monitoring: What Regulators Expect to See

That every audit asks for — and most companies miss one.

The auditor asks: “Can you show me your security logs from last month?” You open a folder. It contains 4,000 text files. You have never looked at them.

This is the logging paradox: every framework requires it, most companies do it, but few do it well. At Metaluxo we review logging and monitoring for SMEs preparing for ISO 27001, GDPR audits, and customer security assessments. This post covers what regulators actually expect.


The five log types every audit checks

1. Authentication logs

Who logged in, when, from where, and whether it succeeded or failed.

What auditors check:

  • Are failed login attempts logged?
  • Is there a threshold for alerting on repeated failures?
  • Can you trace an account compromise back to the initial login?

Evidence: Sample authentication logs showing user, timestamp, source IP, and result.

2. Access logs

Who accessed what data or system and what they did.

What auditors check:

  • Are privileged actions logged separately?
  • Can you reconstruct who accessed a specific customer record?
  • Is there evidence of access reviews?

Evidence: Sample access logs showing user, resource, action, and timestamp.

3. Change logs

What changed in your systems, who made the change, and when.

What auditors check:

  • Are configuration changes logged?
  • Is there approval workflow evidence for significant changes?
  • Can you roll back if a change causes an incident?

Evidence: Change management records and system configuration logs.

4. System logs

What your systems are doing: errors, performance, availability.

What auditors check:

  • Are critical system events logged?
  • Is there monitoring for system availability?
  • Are error logs reviewed and acted upon?

Evidence: System monitoring dashboards and incident tickets linked to log events.

5. Security event logs

Alerts from security tools: firewalls, endpoint protection, intrusion detection.

What auditors check:

  • Are security events logged in a central location?
  • Is there a process for reviewing and escalating alerts?
  • Are false positives tuned to reduce noise?

Evidence: Security alert logs and incident response records.


What “review” actually means

Collecting logs is not enough. Regulators expect you to review them and act on anomalies. This does not mean reading 4,000 files. It means:

  1. Daily automated alerts for critical events (failed admin logins, data exports, configuration changes)
  2. Weekly manual review of high-priority alerts
  3. Monthly summary of security events, trends, and actions taken
  4. Quarterly deep dive into logging coverage and gaps

For a 20-person company, this is 2–3 hours per week. Not zero. Not full-time.


Tools for SMEs

ApproachCostBest for
Cloud-native logging (CloudTrail, Azure Monitor, GCP Logging)Included in cloud spendSingle-cloud startups
Splunk / Datadog / Elastic£500–£2,000/monthMulti-cloud or complex infrastructure
Open source (Graylog, Wazuh)Infrastructure cost onlyTechnical teams with ops capacity
Managed SOC£1,000–£5,000/monthCompanies without internal security staff

At Metaluxo we design logging and monitoring strategies for SMEs as part of our ISO 27001 and vCISO engagements. If your audit is coming up and you are not sure whether your logs will pass, book a free 30-minute consultation and we will assess your coverage.

Common questions

How long must we retain security logs?

GDPR does not specify a log retention period, but 12 months is the standard for security logs. Some frameworks require longer: PCI DSS requires 1 year, with 3 months immediately available.

Do we need a SIEM for a small company?

Not necessarily. A 20-person company can manage with cloud-native logging (CloudTrail, Azure Monitor, Google Cloud Logging) and periodic manual review. A SIEM becomes valuable at 50+ people or with complex infrastructure.

What is log integrity and why does it matter?

Log integrity means logs cannot be altered or deleted without detection. This is critical for forensic investigations and regulatory evidence. Use immutable storage or cryptographic hashing.

Related reading

Send us a message
Message us Book now