Requirements - Non-Functional Profile - NF05 - Audit & Logging

Audit & logging requirements should be defined, and the solution can support them.

Requirement description

NCSC Logging and Protective Monitoring

NCSC Principle 13: Audit information and alerting for customers

This requirement is about ensuring that the solution generates, retains and makes available the audit and logging information needed to support operational management, security monitoring, incident investigation, compliance and governance activities.

The service should have clearly defined audit and logging requirements. The architecture should demonstrate how logs and audit records are generated, protected, retained, accessed and used. Logging arrangements should be proportionate to the sensitivity, criticality and risk profile of the service.

In simple terms:
The organisation knows what needs to be logged, why it needs to be logged, and can demonstrate that the solution captures and manages audit information effectively.

Scoring rubric table – NF05 Audit & Logging

Score What it looks like Typical evidence Key gaps / risks
0 No evidence that audit or logging requirements have been defined. The solution provides little or no ability to investigate operational or security events. No logging standards, audit requirements, monitoring design, retention policies or operational procedures. Significant service risk. Security incidents, operational failures and compliance issues may not be detectable or investigable.
1 Limited evidence that audit and logging have been considered. Logging is inconsistent, incomplete or largely dependent on default platform capabilities. Informal requirements, limited system logs, undocumented assumptions, supplier assertions or isolated logging implementations. High-risk gaps. Important events may not be recorded and audit coverage is insufficient to support investigations.
2 Some audit and logging requirements have been identified and partially implemented. Coverage exists for selected components but is incomplete. Partial logging standards, basic audit trails, limited retention policies, selected monitoring dashboards or security logging capabilities. Significant notable gaps in event coverage, retention arrangements, governance, access controls or operational use of logs.
3 Much of the requirement is met with an acceptable level of evidence. Key audit and logging requirements are defined and implemented across most critical service components. Documented logging requirements, security and operational logs, audit trail specifications, retention policies, monitoring arrangements and incident investigation processes. Notable gaps remain in coverage, consistency, governance, retention management, log protection or integration with monitoring processes. Mitigating action is required.
4 Most of the requirement is met with good levels of evidence. Audit and logging requirements are maintained, governed and aligned to operational and security needs. Approved logging standards, documented event catalogues, retention schedules, access controls, monitoring integration, governance reviews and evidence of regular use during operational and security activities. Minor gaps only. Remaining risks are known, documented and actively managed.
5 Comprehensive evidence that the requirement is met and exceeds expectations in several areas. Audit and logging capabilities are mature, consistently applied and actively support operational improvement, security monitoring and compliance activities. Enterprise-aligned logging strategy, centralised logging, automated analysis, defined audit controls, continuous review processes, monitoring integration and evidence that audit data informs operational and security decision-making. Minimal gaps. Logging and audit capabilities are routinely reviewed, validated and continuously improved.

What assessors should look for

  1. Defined audit requirements
    Evidence that the organisation has identified which user, system, security and administrative activities require auditing.
  2. Defined logging requirements
    Evidence that logging requirements are documented, understood and aligned to operational and security needs.
  3. Coverage across the solution
    Evidence that critical applications, services, integrations and infrastructure components generate appropriate logs and audit records.
  4. Retention and protection
    Evidence that logs are retained appropriately and protected against unauthorised access, modification or deletion.
  5. Operational and security use
    Evidence that logging information is used to support monitoring, incident management, troubleshooting and security investigations.
  6. Governance and maintenance
    Evidence that logging standards, requirements and controls are reviewed and maintained as the solution evolves.

What separates a 3 from a 4 or 5

A score of 3 generally means that audit and logging requirements have been documented and largely implemented, but there are notable weaknesses such as inconsistent coverage, gaps in retention arrangements, unclear ownership or limited evidence that logs are actively used.

A score of 4 requires evidence that logging and audit controls are governed, maintained and routinely used by operational and security teams. Coverage should be largely complete, with only minor gaps remaining.

A score of 5 requires evidence that audit and logging capabilities are embedded within operational practice. Logging data is actively analysed, supports continuous improvement and is consistently used to strengthen service reliability, security and compliance.

Suggested examples of evidence (not SAF-mandated artefacts):

  • Audit and logging requirements specification.
  • Logging standards or policies.
  • Audit trail design documentation.
  • Security monitoring requirements.
  • Retention and archival policies.
  • Logging architecture diagrams.
  • Monitoring and alerting dashboards.
  • Incident investigation reports.
  • Security operations procedures.
  • Governance review records.

Updated: 07 August 2026 (SAF Version 1.1)