IT & Cyber Audit
Audit Log Integrity
If the audit trail can be switched off or altered, no control that relies on it can be trusted โ logging integrity is foundational.
Why the audit trail is itself an audit object
Audit logs on financial and HR systems are the evidence base for almost every other control test; if logging is disabled, gappy or alterable, the auditor cannot rely on the system of internal control and the AGSA will treat the IT general-control environment as deficient. ISSAI and COSO both position reliable logging as foundational to assurance, and POPIA requires that processing of personal information be auditable. AuditPro Core monitors whether audit trails are enabled, protected from tampering and retained for the required period across the entity's critical platforms, so a weakness in the evidence base is caught before it undermines every dependent control.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Systems in scope
23
Logging enabled
20
of 23
Trail gaps
14
this quarter
Tamper-protected
61%
Logging maturity by system
Systems with logging concerns
| System | Issue | Severity |
|---|---|---|
| PERSAL | Disabled for 6 days | High |
| LOGIS | No tamper protection | High |
| Payroll DB | Retention < 90 days | Medium |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Enabled, complete and continuous
Logging must be on for every security-relevant event, without gaps where it was disabled. A trail with holes is often worse than none because it creates false confidence.
Tamper protection
Logs must be write-protected or shipped to an independent store so that the people being monitored cannot edit their own trail. Without this, the log is not evidence.
Retention to match the audit cycle
Trails must be retained long enough to support the regularity audit and any investigation โ typically well beyond a single financial year โ and aligned to records-management and POPIA retention rules.
Privileged-user accountability
The highest-risk actions are taken by administrators, so logging that excludes privileged activity defeats its own purpose. Admin actions must be logged to an account the admin cannot reach.
How AuditPro Core Bridges the Gap
- Coverage monitoring: the platform tracks which critical systems have logging enabled and flags any platform where it is off or partial.
- Tamper-evidence checks: log forwarding and write-protection status are surfaced so unprotected trails are visible.
- Retention assurance: log retention periods are measured against the required audit and POPIA horizons.
- Continuous monitoring: changes to logging configuration are themselves raised as exceptions for review.
Key Takeaways
- A gappy or alterable log undermines every control that depends on it.
- Ship logs to an independent store so the monitored cannot edit their own trail.
- Retention must span the audit cycle and satisfy POPIA, not just the current year.
- Privileged-user actions are the highest risk and must always be logged.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records โ every figure traceable to source.
