Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

N.4.11 Log files

Control Overview

This control mandates that the organization comprehensively records, centralizes, and systematically analyzes event logs across all relevant network environments, operating systems, and applications. Based on a structured risk assessment, the organization must define what constitutes a "relevant event" (such as authentication failures, privilege elevations, policy modifications, or data exports). To ensure these records are legally and forensically defensible, log management must enforce strict access controls, protect logs against unauthorized modification or deletion, synchronize system clocks across all infrastructure nodes using a unified reference time (UTC), and maintain a clear retention baseline (minimum 30 days) for deep security analysis.

note

Applicability Note: This control is fully applicable to the anDREa platform and forms the foundation of our threat detection, forensic investigation, and compliance auditing capabilities.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, moving beyond passive log storage toward a centralized, intelligent telemetry pipeline.

Rather than scattering log trails across isolated platform silos, anDREa aggregates logging data from our entire multi-cloud ecosystem—including Microsoft Azure infrastructure, Google Workspace accounts, and internal myDRE service layers—into a unified monitoring stack. All system clocks are bound natively to Coordinated Universal Time (UTC) to ensure chronological correlation during cross-platform event analysis.

To maintain strict compliance with our internal Retention & Destruction Policy, logs are preserved according to a definitive register detailing their specific purpose and exact retention periods (with all critical security events hitting or exceeding the regulatory minimum). Access to these log repositories is governed by a strict "need-to-know" model, with log integrity protected against tampering to ensure immutable audit trails.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.15 - LoggingMandates that logs recording activities, exceptions, faults, and security events are produced, kept, and regularly reviewed.
ISO/IEC 27001A.05.07 - Threat intelligenceLeverages centralized log inputs to fuel analytical ingestion engines and identify emerging indicators of compromise (IoCs).
Data GovernanceRetention & Destruction PolicyThe authoritative matrix defining lifecycle schedules, storage tiers, and the mandatory retention baseline for security logs.
Operational RegisterLog Purpose & Retention LedgerA complete, detailed list outlining every active log stream, its explicit business/security purpose, and its exact storage duration. (Retention Periods)
Infrastructure BaselinesUTC Synchronisation ConfigurationsAutomated technical policies ensuring all virtual machines, containers, and cloud nodes leverage uniform network time protocols. (A.08.17 - Clock synchronization)

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Multi-cloud log aggregation, automated UTC time synchronization, restricted log access privileges, and clear purpose-driven retention tables are fully operationalized and auditable.