Network and Infrastructure Security
Audit Logging and Monitoring
On an application level, we produce audit logs for all activity and ship logs to a centralised logging system for analysis. All actions taken on production consoles or in the Harmony application are logged.
How it is checked
Logs are shipped off the producing system to a central platform for analysis.
Framework requirements this speaks to
- ISO 27001 A.8.15 (logging)
- ISO 27001 A.8.16 (monitoring activities)
- SOC 2 Common Criteria - Monitoring
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Need the evidence behind this?
Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.