A.8.15 Logging
Control Objective
Logs that record activities, exceptions, faults and other relevant events shall be produced, stored, protected and analysed.
Policy Statement
anDREa implements extensive logging infrastructures across both its core research platform (myDRE) and corporate business tools (Google Workspace). Security, operational, and administrative logs are systematically produced, protected against modification through strict immutability controls, and analyzed through defined programmatic reviews and event-driven investigations.
1. myDRE & Microsoft Azure Log Architecture
Platform and tenant environments maintain comprehensive telemetry to preserve audit trails and detect potential indicators of compromise ($IoCs$):
-
Entra ID Identity Logs: Tracks security and access events, including:
- User sign-in locations and device compliance markers.
- Automated system-generated Risky User and high-risk authentication flags.
- Comprehensive multi-factor authentication (MFA) challenges (See: Logon policy).
- Timestamps, justifications, and approvals for Privileged Identity Management (PIM) role activations (see: Azure PIM Review).
-
Infrastructure Resource Logs: Captures system-level changes, including platform deployment configurations, resource activity tracking, and low-level system faults.
-
Storage and Protection: Infrastructure logs pertaining to research Workspaces are written directly to isolated, customer-specific Log Analytics Workspaces. These repositories are configured to be strictly immutable, meaning log records cannot be modified, deleted, or overridden by any user or administrator.
-
Analysis Cadence: * Identity Baselines: Entra ID authentication and PIM logs are formally extracted and reviewed bi-monthly during scheduled Information Security Management Board (ISMB) Meetings.
-
Resource Telemetry: Resource and deployment logs are systematically analyzed on an event-driven basis (e.g., performing a technical root-cause analysis when a research Virtual Machine (VM) fails to provision).
2. Google Workspace Corporate Logs
Corporate business tools record all operational, collaborative, and organizational actions to maintain corporate compliance:
- Drive Log Events: Comprehensive audit trails capturing all document viewing, creation, modification, downloading, and external sharing configurations (see Drive Log Events).
- Security Controls and Integrity: Log records are natively protected against tampering; editing or deleting historical entries within the console is technically impossible. Administrative access to the underlying Audit and Investigation Tool is restricted exclusively to verified global administrators (see A.08.02 - Privileged access rights).
- Retention & Analysis: Logs are retained dynamically in accordance with core SaaS provider policies. Dedicated log analyses are triggered:
- Mandatory during the formal Onboarding & Offboarding Process of any departing employee or contractor.
- Ad-hoc when an operational anomaly or data-sharing concern arises.