CAIQ v4 Control LOG-01 Extractive Review Standard

How to answer 'Are system, application, and auth logs aggregated into a centralized SIEM?' on a CAIQ

Reviewer Guidance & Pitfalls

Name the centralized logging or SIEM platform (e.g., Datadog, CloudWatch, Papertrail) and describe automated alerting on suspicious login anomalies or IAM changes.

Example Answer Passing Enterprise Audit

Compliant Response Template
Yes. Audit logs, VPC flow logs, and authentication events are streamed in real time to Datadog/CloudWatch with automated alerts triggering for privilege escalations or anomaly spikes (SOC 2, CC7.2).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.