operationsVersion 1SOC2ISO27001NIST800-171
Logging & Monitoring Policy
What Rex Black logs, retention, tamper evidence, and real-time monitoring.
Download PDFSHA-256 46e646d3cd98f22f…
Logging & Monitoring Policy
1. Purpose
Defines what Rex Black logs, how long it is kept, and how it is monitored to detect security-relevant events in near real time and to support investigations after the fact.
2. What is logged
2.1 Application layer (Rex Black app)
- Audit log: every privileged action, sign-in, MFA enrollment, role change, RBAC check failure, SOW send/sign/countersign, vault open/share, integration install/rotate, data export, backup/restore.
- Access log: every API request with
timestamp,userId,orgId,sessionId,route,httpMethod,responseCode,latencyMs,sourceIp,userAgent,requestId. - Sensitive operations additionally record
beforeHashandafterHashof the affected record for tamper evidence. - Logs are structured JSON. PII and Restricted data are never logged as values; keys only.
2.2 Platform
- CloudTrail: all AWS management events across all regions, including data events for S3 buckets storing Confidential / Restricted data and all Lambda invocations in CUI scope.
- VPC Flow Logs: full capture when a VPC is used.
- CloudWatch: Lambda and application logs; metric filters produce security-relevant metrics.
- GuardDuty: all available findings.
- AWS Config: all supported resources; drift alarmed.
- SES: delivery and bounce events.
2.3 Identity / SaaS
- Google Workspace, GitHub, Stripe, ClickUp, Asana admin and audit logs are ingested into CloudWatch Logs via scheduled polling.
3. Tamper evidence
- The application audit log is written both:
- To DynamoDB (hot query).
- To an append-only S3 bucket with Object Lock COMPLIANCE and a hash-chain (each record includes the SHA-256 of the previous record) for tamper evidence.
- Log integrity is verified nightly by recomputing the chain. Failures trigger a P0 incident.
4. Retention
| Log class | Hot (queryable) | Cold | Total |
|---|---|---|---|
| Application audit log | 1 year | S3 Object Lock | 7 years |
| Application access log | 90 days | S3 IA | 1 year |
| CloudTrail | 90 days | S3 IA | 7 years |
| VPC Flow Logs | 30 days | S3 IA | 1 year |
| GuardDuty findings | 90 days | S3 | 7 years |
| SaaS ingested logs | 90 days | S3 IA | 1 year |
5. Clocks
- All Rex Black systems synchronize to NTP (AWS-provided NTP for
AWS workloads,
time.apple.com/time.windows.comfor endpoints). - Timestamps in logs are UTC, ISO-8601.
6. Monitoring and alerting
- CloudWatch alarms on:
- Elevated 5xx rates (rolling 5-minute window).
- Elevated authentication failures per user or per IP.
- RBAC denial spikes.
- GuardDuty high / critical findings.
- KMS policy edits, IAM policy edits, CloudTrail config edits, Object Lock config edits.
- Unexpected egress from Lambda to unknown destinations.
- Alerts route via EventBridge → SNS → on-call (email + phone).
- P0/P1 alerts are acknowledged within SLA; unacknowledged alerts escalate to CEO.
7. Access to logs
- Read access is limited to the Security Officer, on-call engineer, and (read-only, time-boxed) approved investigators.
- Every access to raw logs is itself logged; reading log data produces an audit entry.
- Engineers do not have delete or modify access to logs in any environment.
8. Admin visibility
/admin/auditexposes the application audit log with filters and a verification control that walks the hash chain./admin/securitysummarizes alerting state, unacknowledged findings, and recent privileged actions.
9. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Security Officer | Owns logging configuration and alerting rules. |
| Engineering | Instruments applications; respects the allow-list. |
| On-call | Acknowledges and triages alerts in SLA. |
10. References
012-incident-response-plan.md009-data-classification-and-handling-policy.md005-backup-and-recovery-policy.md
11. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.