Log Management Policy
Purpose
Section titled “Purpose”This policy establishes requirements for the collection, retention, monitoring, and protection of system logs to ensure security monitoring, incident response capabilities, and compliance with SOC2 requirements.
This policy applies to all systems, applications, and infrastructure components that generate logs within our organization’s environment, including but not limited to:
- Application servers
- Security systems and monitoring tools
- Cloud infrastructure and services
- User access and authentication systems
Log Management Requirements
Section titled “Log Management Requirements”Log Collection
Section titled “Log Collection”- All critical systems must generate and forward logs to centralized log management systems
- Logs must be collected in real-time or near real-time
- Log collection must not interfere with system performance
- Failed log transmission must be retried and failures must be alerted
Log Retention
Section titled “Log Retention”- System logs are retained for a minimum of 30 days from the date of generation
- Log retention periods may be extended for systems under investigation or audit
- Logs older than the retention period must be securely deleted
- Critical security events may be archived beyond standard retention periods
Centralized Log Management
Section titled “Centralized Log Management”- All logs are centrally collected and managed through HyperDX
- Application error logs and exceptions are also made available to Sentry for monitoring and alerting
- Log aggregation systems must be highly available and resilient
- Access to log management systems must be restricted to authorized personnel
Log Content and Format
Section titled “Log Content and Format”Required Log Information
Section titled “Required Log Information”All logs must include, where applicable:
- Timestamp (UTC format)
- Source system/application identifier
- Event type and severity level
- User identification (when applicable)
- IP address or network location
- Action performed or attempted
- Success or failure status
- Relevant error codes or messages
Sensitive Data Protection
Section titled “Sensitive Data Protection”- Personal identifiable information (PII) must not be logged in clear text
- Authentication credentials must never be logged
- Payment card information must not be included in logs
- Logs containing sensitive data must be encrypted both in transit and at rest
Log Monitoring and Analysis
Section titled “Log Monitoring and Analysis”Security Event Monitoring
Section titled “Security Event Monitoring”- Logs must be continuously monitored for security events and anomalies
- Privilege escalations and administrative actions must be logged
Performance and Availability Monitoring
Section titled “Performance and Availability Monitoring”- System performance metrics must be logged and monitored
- Application errors and exceptions must trigger appropriate alerts
Access Control and Security
Section titled “Access Control and Security”Log Access Restrictions
Section titled “Log Access Restrictions”- Access to logs must be granted based on the principle of least privilege
- Log access must be authenticated and authorized
- Regular access reviews must be conducted quarterly
Log Integrity Protection
Section titled “Log Integrity Protection”- Logs must be protected from unauthorized modification or deletion
- Log tampering attempts must be detected and alerted
- Cryptographic controls may be used to ensure log integrity
- Backup copies of logs must be maintained securely
Incident Response and Forensics
Section titled “Incident Response and Forensics”Log Preservation
Section titled “Log Preservation”- Logs related to security incidents must be immediately preserved
- Extended retention may be required for legal or regulatory purposes
- Chain of custody must be maintained for logs used in investigations
- Log exports must be performed securely and documented
Analysis and Reporting
Section titled “Analysis and Reporting”- Logs must be readily available for security incident analysis
- Log analysis tools and techniques must be documented
- Regular log reviews must be conducted to identify trends and issues
- Compliance reporting requirements must be supported
Responsibilities
Section titled “Responsibilities”IT Team Responsibilities
Section titled “IT Team Responsibilities”- Implementing and maintaining log collection infrastructure
- Monitoring log management system health and performance
- Ensuring compliance with retention and deletion policies
- Managing access controls and user permissions
- Conducting regular policy reviews and updates
Security Team Responsibilities
Section titled “Security Team Responsibilities”- Monitoring logs for security events and incidents
- Defining security alerting rules and thresholds
- Investigating security-related log events
- Maintaining incident response procedures
Development Team Responsibilities
Section titled “Development Team Responsibilities”- Implementing appropriate logging in applications
- Ensuring log content meets security and compliance requirements
- Avoiding logging of sensitive information
- Supporting log analysis during incident response
Compliance and Audit
Section titled “Compliance and Audit”SOC2 Compliance
Section titled “SOC2 Compliance”- Log management practices must support SOC2 Type 2 audit requirements
- Continuous monitoring controls must be documented and tested
- Log management effectiveness must be regularly assessed
- Evidence of log management controls must be maintained
Audit Trail Requirements
Section titled “Audit Trail Requirements”- Complete audit trails must be maintained for all critical systems
- Audit logs must be tamper-evident and protected from unauthorized access
- Regular audit log reviews must be conducted and documented
- Audit findings must be addressed promptly
Policy Review
Section titled “Policy Review”- This policy will be reviewed annually and updated as necessary to reflect changes in technology, business needs, or regulatory requirements.
- Last reviewed/updated: 2026-08-25
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
