SIG Lite Control LOG-04 Extractive Review Standard

How to answer 'Are security audit logs protected against unauthorized modification or deletion?' on a SIG Lite

Reviewer Guidance & Pitfalls

Explain write-once-read-many (WORM) storage, IAM policies preventing log deletion even by administrators, and immutable S3 bucket lock policies.

Example Answer Passing Enterprise Audit

Compliant Response Template
Security audit logs are stored in dedicated, isolated log buckets with Object Lock (WORM) enabled; IAM policies restrict all users and services from modifying or deleting audit trails (SOC 2, CC7.2).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.