Skip to content

Log Management Policy

This policy establishes requirements for the collection, retention, monitoring, and protection of system logs to ensure security monitoring, incident response capabilities, and compliance with SOC2 requirements.

This policy applies to all systems, applications, and infrastructure components that generate logs within our organization’s environment, including but not limited to:

  • Application servers
  • Security systems and monitoring tools
  • Cloud infrastructure and services
  • User access and authentication systems
  • All critical systems must generate and forward logs to centralized log management systems
  • Logs must be collected in real-time or near real-time
  • Log collection must not interfere with system performance
  • Failed log transmission must be retried and failures must be alerted
  • System logs are retained for a minimum of 30 days from the date of generation
  • Log retention periods may be extended for systems under investigation or audit
  • Logs older than the retention period must be securely deleted
  • Critical security events may be archived beyond standard retention periods
  • All logs are centrally collected and managed through HyperDX
  • Application error logs and exceptions are also made available to Sentry for monitoring and alerting
  • Log aggregation systems must be highly available and resilient
  • Access to log management systems must be restricted to authorized personnel

All logs must include, where applicable:

  • Timestamp (UTC format)
  • Source system/application identifier
  • Event type and severity level
  • User identification (when applicable)
  • IP address or network location
  • Action performed or attempted
  • Success or failure status
  • Relevant error codes or messages
  • Personal identifiable information (PII) must not be logged in clear text
  • Authentication credentials must never be logged
  • Payment card information must not be included in logs
  • Logs containing sensitive data must be encrypted both in transit and at rest
  • Logs must be continuously monitored for security events and anomalies
  • Privilege escalations and administrative actions must be logged
  • System performance metrics must be logged and monitored
  • Application errors and exceptions must trigger appropriate alerts
  • Access to logs must be granted based on the principle of least privilege
  • Log access must be authenticated and authorized
  • Regular access reviews must be conducted quarterly
  • Logs must be protected from unauthorized modification or deletion
  • Log tampering attempts must be detected and alerted
  • Cryptographic controls may be used to ensure log integrity
  • Backup copies of logs must be maintained securely
  • Logs related to security incidents must be immediately preserved
  • Extended retention may be required for legal or regulatory purposes
  • Chain of custody must be maintained for logs used in investigations
  • Log exports must be performed securely and documented
  • Logs must be readily available for security incident analysis
  • Log analysis tools and techniques must be documented
  • Regular log reviews must be conducted to identify trends and issues
  • Compliance reporting requirements must be supported
  • Implementing and maintaining log collection infrastructure
  • Monitoring log management system health and performance
  • Ensuring compliance with retention and deletion policies
  • Managing access controls and user permissions
  • Conducting regular policy reviews and updates
  • Monitoring logs for security events and incidents
  • Defining security alerting rules and thresholds
  • Investigating security-related log events
  • Maintaining incident response procedures
  • Implementing appropriate logging in applications
  • Ensuring log content meets security and compliance requirements
  • Avoiding logging of sensitive information
  • Supporting log analysis during incident response
  • Log management practices must support SOC2 Type 2 audit requirements
  • Continuous monitoring controls must be documented and tested
  • Log management effectiveness must be regularly assessed
  • Evidence of log management controls must be maintained
  • Complete audit trails must be maintained for all critical systems
  • Audit logs must be tamper-evident and protected from unauthorized access
  • Regular audit log reviews must be conducted and documented
  • Audit findings must be addressed promptly
  • This policy will be reviewed annually and updated as necessary to reflect changes in technology, business needs, or regulatory requirements.
  • Last reviewed/updated: 2026-08-25

Internal & Confidential: This page is only available in the internal handbook and contains confidential information.