Compliance logging for Windows
Compliance logging for Windows: the controls your auditors test, and the evidence to show them.
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. It supports the logging, file integrity monitoring, data minimisation and delivery controls that PCI DSS, UK GDPR, DORA, NIS2, HIPAA, ISO/IEC 27001 and SOC 2 ask about. Meeting the requirement stays with you.
- PCI DSS v4.0.1
- UK GDPR
- DORA
- NIS2
- HIPAA
- ISO/IEC 27001:2022
- SOC 2
In short
DPLens supports compliance logging on Windows for PCI DSS v4.0.1, UK GDPR, DORA, NIS2, HIPAA, ISO/IEC 27001 and SOC 2. It gives you the logging, change-detection, minimisation and delivery controls auditors test, and the evidence to show them. On each Windows host it collects event logs and files, scans for file changes every 15 minutes, hourly or daily, masks card numbers and personal data before anything leaves, delivers over TLS with a disk-backed cache, and keeps a tamper-evident audit trail of changes made to the agent itself. DPLens Manager, included in every subscription, configures and monitors the whole fleet centrally.
These pages explain how DPLens features relate to published requirements. They are not legal advice and not an audit opinion. Your assessor, auditor, DPO or counsel decides whether your controls meet a requirement. DPLens Ltd holds no certification or attestation for these frameworks, and using DPLens does not confer one.
Control mapping
How DPLens supports each framework
Each row names the requirement, what the agent does towards it, and the artefact you can put in front of an assessor. The framework pages go further, with a "what you do" column for every row.
| Framework | Requirement | How DPLens supports it | Evidence it produces |
|---|---|---|---|
| PCI DSS v4.0.1 | 10.2–10.3: audit logs captured, protected and promptly backed up to a central log server | Collects any Windows Event Log channel and log files, and delivers them off the host as they are collected. TLS with certificate validation on by default; mutual TLS where the receiver requires it. Disk-backed delivery with optional Splunk indexer acknowledgement. Nothing is dropped silently: every drop is counted. | The agent's source and destination settings; per-destination delivery state and cache depth; losses by cause on the Overview page; fleet health in DPLens Manager |
| PCI DSS v4.0.1 | 11.5.2: change-detection mechanism that compares critical files at least once weekly and alerts on unauthorised change | File integrity monitoring (FIM) of files, folders and wildcards, scanned every 15 minutes, hourly or daily. Changes are reported as events through your pipeline to your SIEM, where you alert on them. | FIM change events in your SIEM; an audit-log entry for every re-baseline |
| PCI DSS v4.0.1 | Requirement 3: PAN unreadable wherever it is stored, including logs | Card-number masking applies before events reach the disk cache or the network: redact, keep the last few digits, or replace with a keyed hash. | Masking rules in configuration; per-rule mask counts; audit-log entries for masking policy changes |
| UK GDPR | Art. 5(1)(c) data minimisation; Art. 25 data protection by design and by default; Art. 32 security of processing | Filters drop events you do not need, and masking redacts or pseudonymises email addresses, IP addresses, phone numbers, UK National Insurance numbers and patterns you define, on the host and before egress. No telemetry: event data is never sent to DPLens Ltd. | Filter and mask rules in configuration; measured in/out counts per stage; audit log of masking policy changes |
| DORA | ICT risk management, detection of anomalous activity, and ICT third-party risk (Regulation (EU) 2022/2554) | Delivery to several destinations at once, ordered failover, per-destination disk cache, and offline operation with no vendor control plane. Output in open formats (syslog, NDJSON, OpenTelemetry's OTLP) keeps your exit options open. | Delivery and failover states; signed releases with SHA-256 checksums and CycloneDX and SPDX SBOMs for your third-party assessment |
| NIS2 | Art. 21 cybersecurity risk-management measures, including incident handling, business continuity and supply-chain security (Directive (EU) 2022/2555) | Collection and reliable delivery of the Windows telemetry your detection depends on; FIM; tamper-evident record of agent changes; a published, verifiable software supply chain. | Collection coverage and losses on the Overview page; the audit log; release signatures and SBOMs |
| HIPAA Security Rule | 45 CFR §164.312(b) audit controls; §164.312(c)(1) integrity; §164.312(e)(1) transmission security | Records and forwards Windows activity from systems that hold ePHI; masks identifiers before egress; TLS with certificate validation on by default to your SIEM. | Event streams in your SIEM; TLS destination settings; mask counts and audit-log entries |
| ISO/IEC 27001:2022 and SOC 2 | Annex A 8.15 Logging, 8.16 Monitoring activities, 8.11 Data masking, 8.32 Change management; SOC 2 CC7.1, CC7.2, CC8.1 | Central configuration in DPLens Manager, with validated, all-or-nothing applies and rollback; a tamper-evident audit trail of who changed what; per-source health and coverage; FIM for configuration drift. | The audit trail and its verification status; the agent configuration under your change control |
By framework
Framework guides
Each guide paraphrases what the framework asks for, maps it to DPLens, and sets out what you do alongside it.
PCI DSS v4.0.1
Requirement 10 logging and 11.5.2 change detection
Audit-log capture and protection, FIM at least weekly, PAN masking before egress, and the evidence a QSA asks for.
Read more →UK GDPR
Log minimisation at source
Filter and mask personal data on the host so less of it reaches your SIEM, and pseudonymise what you still need to correlate.
Read more →DORA
ICT logging and resilience
Detection, delivery through outages, and third-party risk for financial entities running Windows estates.
Read more →NIS2
Logging and incident detection
Article 21 measures, and a note on the UK's NIS Regulations 2018.
Read more →HIPAA
Audit controls for Windows logs
45 CFR §164.312 audit controls, integrity and transmission security on Windows systems that hold ePHI.
Read more →ISO 27001 and SOC 2
Logging, monitoring and change evidence
Annex A 8.15 and 8.16, and the SOC 2 monitoring and change-management criteria.
Read more →Evidence
What you can show an auditor
Everything below comes from the agent or the release itself. None of it needs a vendor portal.
01
The agent's audit trail
A tamper-evident record of sign-ins and failures, configuration applies and rollbacks, password, certificate, licence and masking policy changes, file-integrity re-baselines and start-up checks. The console shows whether it verifies. Ship it to your SIEM so it outlives the machine.
02
The configuration
One configuration holds every source, stage and destination, managed centrally in DPLens Manager. Keep it under change control and you have a reviewable history of what is collected, what is filtered, what is masked and where it goes.
03
Counts, not estimates
Every drop, mask, aggregation and failover increments a counter shown on the Overview page and attributed to the rule that caused it. Collection coverage shows a channel that is empty or a path that matches nothing.
04
A verifiable release
Authenticode-signed releases with SHA-256 checksums and software bills of materials in CycloneDX and SPDX, for your supplier and software-supply-chain reviews.
FAQ
Questions compliance teams ask
Is DPLens PCI DSS, HIPAA or GDPR compliant?
Software is not compliant on its own; organisations are. DPLens provides capabilities that support specific controls and produces evidence for them. Your assessor or auditor judges whether your controls, of which DPLens may be one part, meet the requirement.
Does any log data leave our network?
Only to the destinations you configure. DPLens has no telemetry, no licensing service and no cloud control plane, and upgrades happen only when you roll them out. The one optional exception is the public-IP enrichment, which is off unless you add it and can point at an endpoint of your choosing.
How is the audit trail protected?
The audit trail is tamper-evident: any alteration or removal of a record shows up, and the console shows whether it verifies. Deliver it to your SIEM as it is written and the record outlives the machine.
Can we run DPLens in an air-gapped or regulated network?
Yes. The licence is verified offline, nothing needs internet access, and DPLens Manager is self-hosted and air-gap capable. See air-gapped log collection.
Related
Solutions behind these controls
Windows file integrity monitoring
Scheduled change detection in the agent you already run.
Read more →Log masking and PII redaction
Mask card numbers and personal data before they leave the host.
Read more →Trust Centre
How DPLens is built, signed and verified, and how to report a vulnerability.
Read more →See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.