How should teams handle Logging under ISO/IEC 27017?
Define the required event categories and fields before comparing services. Include security-relevant identity and access events, customer and provider administrative actions visible to the customer, configuration changes, application and workload events, and incident-relevant service events where they apply. The customer should verify that the named service and tier meet those requirements; the provider should supply logging capabilities. In IaaS, the provider's responsibility can stop at infrastructure components while the customer logs its own virtual machines and applications.
Apply a separate branch to delegated privileged operations. Clause 12.4.3 says the operation and its performance should be logged, and the customer should decide whether provider logging is appropriate or whether additional customer logging is needed. Ask which clock the provider uses and how customer systems can synchronize to it; without synchronization, events from both sides can be difficult to reconcile.
Treat service monitoring as a capability built on records and service signals, not as another name for a log. CLD.12.4.5 says the provider should document capabilities that let the customer monitor specified aspects relevant to its use, such as detecting use of the service to attack others or leakage of sensitive data. Access should expose only the customer's own service instances, the monitoring data should be consistent with event logs, and it should help assess service-level terms.
Set event retention, protection, export delay, alert thresholds, and response times from the customer's risks, incident needs, laws, contracts, records rules, and technical constraints. ISO/IEC 27017:2015 does not supply one retention number or require a particular monitoring product.
- Name the owner for each event source, provider capability, export, detection rule, investigation step, escalation, retention decision, and review.
- Record the service and tier, event and required fields, responsible party, timestamp source, access and protection, retention, export timing, alert route, evidence location, exception, and next review trigger.
- Record any event, retention, timestamp, export, or monitoring gap caused by the service tier or provider and decide whether to add capability, change the service, or accept the risk.
ISO lists edition 1, published in December 2015, as guidance for cloud service customers and providers and identifies a revision under development.
The identical 2015 recommendation allocates event and privileged-operation logging, clock information, and service-monitoring capabilities between customer and provider.