SIG Lite
Control LOG-04
Extractive Review Standard
How to answer 'Are security audit logs protected against unauthorized modification or deletion?' on a SIG Lite
Reviewer Guidance & Pitfalls
Explain write-once-read-many (WORM) storage, IAM policies preventing log deletion even by administrators, and immutable S3 bucket lock policies.
Example Answer Passing Enterprise Audit
Compliant Response Template
Security audit logs are stored in dedicated, isolated log buckets with Object Lock (WORM) enabled; IAM policies restrict all users and services from modifying or deleting audit trails (SOC 2, CC7.2).
Filling out a CAIQ or SIG Lite right now?
QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.
Zero spam. 100% confidential. No credit card required.