Logging & Monitoring Policy
Governs how Finaisse logs security-relevant activity and monitors its systems for threats and availability. Subordinate to the Information Security Policy.
| Policy owner | Security & Infrastructure Owner (Sekhar) |
| Applies to | All Finaisse systems and services |
| Effective | 2026-08-27 (v0.1 draft) |
| Review cadence | Annual + on major architecture change |
| Classification | Internal-confidential |
| ISO / SOC 2 | A.8.15–8.16 · SOC 2 CC7.2, CC7.3 |
1. Purpose
Ensure security-relevant events are logged, retained, and monitored so incidents can be detected, investigated, and evidenced.
2. Logging
- Security-relevant actions (authentication, authorisation decisions, administrative operations, data-affecting AI decisions) are logged and attributable — the "immutable auditability" principle.
- No secrets, credentials, or unredacted Restricted data are written to logs. AI-decision reasoning stored in the intelligence log is treated as PII and access-controlled.
- Application logs carry no full prompt/response content; token-usage and decision metadata are captured (see Observability).
3. Monitoring & detection
- 🎯 Target (AWS) — the Day-1 detection baseline: CloudTrail, GuardDuty, Security Hub, VPC Flow Logs, and WAF logging — a production go-live blocker (F-11).
- Alerts route to the security owner; suspected incidents follow the Incident Response Policy.
4. Retention & protection
- Logs are retained per the Data Classification & Retention Policy and protected from tampering.
- 🎯 Target — define per-log-type retention and centralised, access-controlled log storage before production.
5. Review
Reviewed annually and on major architecture change.
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Security & Infrastructure Owner | Initial draft |