Batch Register

Log collection and forwarding

None of the held texts sets a fixed period on this consumer; every row below reads no period set by the text. Paste one job that feeds this consumer, for example syslog_forward_batch, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.

Matched on the job name or the consumer column by these words: log forward, log forwarding, log collection, log shipping, syslog forward, log ingest, log collector, log export, log forwarder. A backup, replication, feed or return job in this class is expected to name a fallback; a blank one is a finding.

The clock each rule sets

RegimeClockClause
ISO 27001no clockISO 27001 8.15 Logging
SP 800-53no clockSP 800-53 AU-6 Audit record review, analysis, and reportinga defined frequency
HIPAAno clockHIPAA 164.308(a)(1)(ii)(D) Information System Activity Review (Required)

Questions this page answers

How often does ISO/IEC 27001:2022 require log collection and forwarding?

The held text of ISO 27001 8.15 (Logging) sets no fixed period: no period set by the text. Produce, store, protect and analyse logs of activities, exceptions and faults.

How often does NIST SP 800-53 Rev 5 require log collection and forwarding?

The held text of SP 800-53 AU-6 (Audit record review, analysis, and reporting) sets no fixed period: a defined frequency. Requires audit records to be reviewed and analysed on a defined frequency for indications of organization-defined inappropriate or unusual activity and its likely impact, findings to be reported to defined personnel, and the depth of review to be increased when credible information changes the risk.

How often does HIPAA Security Rule require log collection and forwarding?

The held text of HIPAA 164.308(a)(1)(ii)(D) (Information System Activity Review (Required)) sets no fixed period: no period set by the text. Regularly review audit logs, access reports, and security incident tracking reports. NIST recommends defined review frequency, SIEM integration, anomaly detection, and documented review evidence.

What does the register ask the owner of a log collection and forwarding job?

If this job stops, which systems fall silent in the review, and who notices?

The clauses in full

ISO 27001 8.15 Loggingthe standard's page

Produce, store, protect and analyse logs of activities, exceptions and faults.

Guidance beside it, ISO 27002 8.15: Requires logs to be produced, stored, protected and analysed, covering activities, exceptions, faults and any other event of relevance. Older source material adds that records of user activity, exceptions and security events should be retained for an agreed period to support later investigation and access control monitoring, and that faults should be logged, analysed and acted on.

What an assessor asks to see: log_collection_policy; log_storage_and_protection; log_review_and_analysis; log_retention_and_disposal. Where it usually falls short: Inconsistent log collection across systems

SP 800-53 AU-6 Audit record review, analysis, and reportingthe standard's page

Requires audit records to be reviewed and analysed on a defined frequency for indications of organization-defined inappropriate or unusual activity and its likely impact, findings to be reported to defined personnel, and the depth of review to be increased when credible information changes the risk.

What an assessor asks to see: Defined review frequency and the activity indicators being looked for; Completed review records with reviewer, date and findings; Reports issued to the defined recipients and evidence of follow-up; Record of a review level adjustment made in response to changed risk. Where it usually falls short: Review is automated alerting only, with no periodic analytical review for slow patterns

HIPAA 164.308(a)(1)(ii)(D) Information System Activity Review (Required)the standard's page

Regularly review audit logs, access reports, and security incident tracking reports. NIST recommends defined review frequency, SIEM integration, anomaly detection, and documented review evidence.

What an assessor asks to see: Log review procedure; SIEM correlation rules; Sampled log review records; Anomaly investigation tickets. Where it usually falls short: Logs collected but never reviewed

Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register