ISO/IEC 27001:2022 and SOC 2

Logging, monitoring and change evidence for ISO 27001 Annex A 8.15 and SOC 2.

Auditors for both ask the same practical questions: are the right events logged, are the logs protected, is anyone watching, and can you show who changed what? DPLens answers the Windows part of each with configuration and records you can hand over.

  • A.8.15 Logging
  • A.8.16 Monitoring
  • A.8.32 Change management
  • CC7.2
  • CC8.1

In short

DPLens supports ISO 27001 Annex A 8.15 logging and SOC 2 monitoring evidence on Windows. For an ISO/IEC 27001 certification audit or a SOC 2 examination, it supports logging, monitoring, data masking and change-management controls on Windows hosts. It collects and reliably delivers event logs and file-integrity changes to your SIEM, masks sensitive values before egress, and keeps a tamper-evident audit trail of every change made to the agent, with the account and time. DPLens Manager, included in every subscription, gives you central configuration and fleet health monitoring across every host. It is a control you operate, and a source of evidence within your ISMS.

Not legal or audit advice.

This page relates DPLens features to ISO/IEC 27001:2022 Annex A and the SOC 2 Trust Services Criteria as we read them. It is not audit advice. Your certification body or service auditor decides whether your controls are suitably designed and operating. DPLens Ltd does not hold an ISO/IEC 27001 certificate or a SOC 2 report; ask us what vendor-risk evidence we can provide.

Last reviewed 1 October 2026.

The frameworks

What ISO 27001 and SOC 2 ask for

Paraphrases of the controls and criteria most often tested against a log agent.

A.8.15

Logging

Logs that record activities, exceptions, faults and other relevant events are produced, stored, protected and analysed.

A.8.16

Monitoring activities

Networks, systems and applications are monitored for anomalous behaviour, and action is taken to evaluate potential incidents.

A.8.11 and A.8.32

Data masking and change management

Data is masked in line with your access control policy and business needs. Changes to information processing facilities and systems follow change-management procedures.

CC7.1, CC7.2, CC8.1

SOC 2 common criteria

Detection and monitoring procedures identify configuration changes that introduce vulnerabilities (CC7.1); system components are monitored for anomalies indicating malicious acts, natural disasters and errors (CC7.2); changes are authorised, tested, approved and implemented (CC8.1).

Control map

ISO 27001 and SOC 2 mapping

ISO/IEC 27001:2022 Annex A controls and SOC 2 criteria mapped to DPLens capabilities and what you do
RequirementHow DPLens supports itWhat you do
A.8.15 LoggingCollects any Windows Event Log channel and log files; delivers over TLS with a disk cache; every drop counted and attributed to its ruleA logging policy: what is logged, retention and log protection in your SIEM
A.8.16 Monitoring; CC7.2Feeds your SIEM with host telemetry; component health, delivery state and losses show when collection itself is failingDetection rules, alert handling and evidence that alerts are followed up
A.8.11 Data maskingDetectors for card numbers, email, IP addresses, phone, UK NI and US SSN, plus your own patterns; redact, partial, token or keyed hash, before egressDecide which data to mask under your access control policy
A.8.32 Change management; CC8.1Configuration as code, managed centrally in DPLens Manager; changes are staged, validated as a whole, applied as one set and can be rolled back; every apply and rollback is in the tamper-evident audit trailApproval and testing of changes, and change control of the configuration
A.8.9 Configuration management; CC7.1File integrity monitoring of files and folders every 15 minutes, hourly or daily, with re-baselines recorded in the audit logDefine baselines and watch lists, and investigate unexpected changes
A.8.17 Clock synchronisationNormalises timestamps to UTC at collectionSynchronise host clocks
A.8.24 Cryptography; CC6.7 TransmissionTLS with certificate validation on by default; mutual TLS where the receiver requires it; secrets protected on the machineCertificate management and choosing TLS for each destination
A.5.21 ICT supply chain; CC9.2 VendorsSigned releases, SHA-256 checksums, CycloneDX and SPDX SBOMs; no telemetry or vendor control planeSupplier assessment and verifying each download

Evidence

What to put in the audit file

  • The agent's audit trail: sign-ins and failures, configuration applies and rollbacks, password, certificate, licence and masking policy changes, file-integrity re-baselines and start-up checks, each with account and UTC time
  • A screenshot of Settings → Audit showing the audit trail verifies
  • Configuration history from your change control, matched to change tickets
  • Overview page captures of collection coverage, the pipeline funnel and losses, and fleet health from DPLens Manager
  • FIM change events in your SIEM and the alerts raised from them
  • The release's checksums, signature check and SBOM for the deployed version

A type 2 SOC 2 examination looks at operation over a period, so ship the audit trail to your SIEM as it is written. A file on one host is weaker evidence than a record that also exists somewhere the host's administrators cannot change. For the controls behind this evidence, see Windows file integrity monitoring, log masking and the Trust Centre.

FAQ

Questions auditors and engineers ask

How does the audit trail evidence changes to collection?

It records every sign-in, apply and rollback with the account and time, and it is tamper-evident: a changed or removed record shows up, and the console reports it. Ship it off the host as it is written and the record outlives the machine.

Can we show who changed a filter that dropped events?

Yes. Every configuration apply is recorded with the account and time, and every dropped event is counted against the rule that dropped it.

What can DPLens provide for our supplier review?

Signed releases with SHA-256 checksums, CycloneDX and SPDX SBOMs, and a description of how the software is built, signed and verified. Contact us for the evidence your supplier review needs.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.