ISO/IEC 27001:2022 and SOC 2
Logging, monitoring and change evidence for ISO 27001 Annex A 8.15 and SOC 2.
Auditors for both ask the same practical questions: are the right events logged, are the logs protected, is anyone watching, and can you show who changed what? DPLens answers the Windows part of each with configuration and records you can hand over.
- A.8.15 Logging
- A.8.16 Monitoring
- A.8.32 Change management
- CC7.2
- CC8.1
In short
DPLens supports ISO 27001 Annex A 8.15 logging and SOC 2 monitoring evidence on Windows. For an ISO/IEC 27001 certification audit or a SOC 2 examination, it supports logging, monitoring, data masking and change-management controls on Windows hosts. It collects and reliably delivers event logs and file-integrity changes to your SIEM, masks sensitive values before egress, and keeps a tamper-evident audit trail of every change made to the agent, with the account and time. DPLens Manager, included in every subscription, gives you central configuration and fleet health monitoring across every host. It is a control you operate, and a source of evidence within your ISMS.
This page relates DPLens features to ISO/IEC 27001:2022 Annex A and the SOC 2 Trust Services Criteria as we read them. It is not audit advice. Your certification body or service auditor decides whether your controls are suitably designed and operating. DPLens Ltd does not hold an ISO/IEC 27001 certificate or a SOC 2 report; ask us what vendor-risk evidence we can provide.
The frameworks
What ISO 27001 and SOC 2 ask for
Paraphrases of the controls and criteria most often tested against a log agent.
A.8.15
Logging
Logs that record activities, exceptions, faults and other relevant events are produced, stored, protected and analysed.
A.8.16
Monitoring activities
Networks, systems and applications are monitored for anomalous behaviour, and action is taken to evaluate potential incidents.
A.8.11 and A.8.32
Data masking and change management
Data is masked in line with your access control policy and business needs. Changes to information processing facilities and systems follow change-management procedures.
CC7.1, CC7.2, CC8.1
SOC 2 common criteria
Detection and monitoring procedures identify configuration changes that introduce vulnerabilities (CC7.1); system components are monitored for anomalies indicating malicious acts, natural disasters and errors (CC7.2); changes are authorised, tested, approved and implemented (CC8.1).
Control map
ISO 27001 and SOC 2 mapping
| Requirement | How DPLens supports it | What you do |
|---|---|---|
| A.8.15 Logging | Collects any Windows Event Log channel and log files; delivers over TLS with a disk cache; every drop counted and attributed to its rule | A logging policy: what is logged, retention and log protection in your SIEM |
| A.8.16 Monitoring; CC7.2 | Feeds your SIEM with host telemetry; component health, delivery state and losses show when collection itself is failing | Detection rules, alert handling and evidence that alerts are followed up |
| A.8.11 Data masking | Detectors for card numbers, email, IP addresses, phone, UK NI and US SSN, plus your own patterns; redact, partial, token or keyed hash, before egress | Decide which data to mask under your access control policy |
| A.8.32 Change management; CC8.1 | Configuration as code, managed centrally in DPLens Manager; changes are staged, validated as a whole, applied as one set and can be rolled back; every apply and rollback is in the tamper-evident audit trail | Approval and testing of changes, and change control of the configuration |
| A.8.9 Configuration management; CC7.1 | File integrity monitoring of files and folders every 15 minutes, hourly or daily, with re-baselines recorded in the audit log | Define baselines and watch lists, and investigate unexpected changes |
| A.8.17 Clock synchronisation | Normalises timestamps to UTC at collection | Synchronise host clocks |
| A.8.24 Cryptography; CC6.7 Transmission | TLS with certificate validation on by default; mutual TLS where the receiver requires it; secrets protected on the machine | Certificate management and choosing TLS for each destination |
| A.5.21 ICT supply chain; CC9.2 Vendors | Signed releases, SHA-256 checksums, CycloneDX and SPDX SBOMs; no telemetry or vendor control plane | Supplier assessment and verifying each download |
Evidence
What to put in the audit file
- The agent's audit trail: sign-ins and failures, configuration applies and rollbacks, password, certificate, licence and masking policy changes, file-integrity re-baselines and start-up checks, each with account and UTC time
- A screenshot of Settings → Audit showing the audit trail verifies
- Configuration history from your change control, matched to change tickets
- Overview page captures of collection coverage, the pipeline funnel and losses, and fleet health from DPLens Manager
- FIM change events in your SIEM and the alerts raised from them
- The release's checksums, signature check and SBOM for the deployed version
A type 2 SOC 2 examination looks at operation over a period, so ship the audit trail to your SIEM as it is written. A file on one host is weaker evidence than a record that also exists somewhere the host's administrators cannot change. For the controls behind this evidence, see Windows file integrity monitoring, log masking and the Trust Centre.
How to do it
In the documentation
FAQ
Questions auditors and engineers ask
How does the audit trail evidence changes to collection?
It records every sign-in, apply and rollback with the account and time, and it is tamper-evident: a changed or removed record shows up, and the console reports it. Ship it off the host as it is written and the record outlives the machine.
Can we show who changed a filter that dropped events?
Yes. Every configuration apply is recorded with the account and time, and every dropped event is counted against the rule that dropped it.
What can DPLens provide for our supplier review?
Signed releases with SHA-256 checksums, CycloneDX and SPDX SBOMs, and a description of how the software is built, signed and verified. Contact us for the evidence your supplier review needs.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.