How to answer
Do you log and monitor access to production systems?
Two questions in one: what you record, and what happens when something in the record is worth waking up for.
Yes. Application, infrastructure and access logs are centralised in [your logging service], retained for [12 months], and alerting is configured for authentication failures, privilege changes and unusual administrative activity.
Square brackets are yours to fill in. FillTrust grades an answer like this confirmed in your documents when your documents support it.
- Answered from
- Your information security policy, and the monitoring section of your SOC 2 report.
- Evidence to attach
- Rarely anything. Where it is asked for, a screenshot of a dashboard or an alert rule is enough.
- Where it is asked
- CAIQ v4.0 · LOG-03SIG LiteISO 27001 Annex A · A.8.15
Almost every team logs. Rather fewer monitor, and this question is asking about both, so the strongest answer separates them.
What you record. Name the sources: application logs, infrastructure and platform logs, authentication events, and administrative actions in your cloud console. Then name where they go. "Centralised in a managed logging service" is a real answer; "each service writes its own logs" is a weaker one that invites the follow-up about correlation.
How long you keep them. This is asked more often than almost anything else on the page and small teams frequently do not know. Whatever your provider's default retention is, that is your answer until you change it, and it is often 30 days: shorter than the 90 days or 12 months most reviewers expect. Finding this out before answering is ten minutes of work that prevents a correction later. If it is 30 days, say 30 days. A reviewer can accept a short window they were told about; they take a much dimmer view of a number that turns out to be wrong.
What you alert on. This is the half that turns logging into monitoring, and the honest small-company answer is a short list: failed authentication above a threshold, changes to privileged access, and anything hitting an error budget. Three alert rules that fire into a channel somebody reads is a real control. Saying "24/7 monitoring" when it means an on-call rotation of two people is defensible if you say it that way, and misleading if you leave it at the phrase.
The tamper question. Some questionnaires ask whether logs are protected from modification. If your logs go to a managed service with append-only retention, say so, because it is a genuinely good answer that most small teams have without realising.
This one usually grades as confirmed, because policies tend to cover it in general terms. What it will not cover is your retention period, so that is the sentence worth adding to the policy.
How this one goes wrong
Specific to this question, not general advice.
- Answering yes because the logs exist. The question is about monitoring, and logs nobody looks at and nothing alerts on are storage, not a control.
- Not knowing your retention period. It is the single most common follow-up, and "the default" is not an answer a reviewer can write down.
- Claiming a SIEM because your cloud provider offers one. If it is not receiving your logs, it is not part of your answer.