Skip to main content

operationsVersion 1SOC2ISO27001NIST800-171

Logging & Monitoring Policy

What Rex Black logs, retention, tamper evidence, and real-time monitoring.

Download PDFSHA-256 46e646d3cd98f22f…

Logging & Monitoring Policy

1. Purpose

Defines what Rex Black logs, how long it is kept, and how it is monitored to detect security-relevant events in near real time and to support investigations after the fact.

2. What is logged

2.1 Application layer (Rex Black app)

  • Audit log: every privileged action, sign-in, MFA enrollment, role change, RBAC check failure, SOW send/sign/countersign, vault open/share, integration install/rotate, data export, backup/restore.
  • Access log: every API request with timestamp, userId, orgId, sessionId, route, httpMethod, responseCode, latencyMs, sourceIp, userAgent, requestId.
  • Sensitive operations additionally record beforeHash and afterHash of the affected record for tamper evidence.
  • Logs are structured JSON. PII and Restricted data are never logged as values; keys only.

2.2 Platform

  • CloudTrail: all AWS management events across all regions, including data events for S3 buckets storing Confidential / Restricted data and all Lambda invocations in CUI scope.
  • VPC Flow Logs: full capture when a VPC is used.
  • CloudWatch: Lambda and application logs; metric filters produce security-relevant metrics.
  • GuardDuty: all available findings.
  • AWS Config: all supported resources; drift alarmed.
  • SES: delivery and bounce events.

2.3 Identity / SaaS

  • Google Workspace, GitHub, Stripe, ClickUp, Asana admin and audit logs are ingested into CloudWatch Logs via scheduled polling.

3. Tamper evidence

  1. The application audit log is written both:
    • To DynamoDB (hot query).
    • To an append-only S3 bucket with Object Lock COMPLIANCE and a hash-chain (each record includes the SHA-256 of the previous record) for tamper evidence.
  2. Log integrity is verified nightly by recomputing the chain. Failures trigger a P0 incident.

4. Retention

Log class Hot (queryable) Cold Total
Application audit log 1 year S3 Object Lock 7 years
Application access log 90 days S3 IA 1 year
CloudTrail 90 days S3 IA 7 years
VPC Flow Logs 30 days S3 IA 1 year
GuardDuty findings 90 days S3 7 years
SaaS ingested logs 90 days S3 IA 1 year

5. Clocks

  1. All Rex Black systems synchronize to NTP (AWS-provided NTP for AWS workloads, time.apple.com/time.windows.com for endpoints).
  2. Timestamps in logs are UTC, ISO-8601.

6. Monitoring and alerting

  1. CloudWatch alarms on:
    • Elevated 5xx rates (rolling 5-minute window).
    • Elevated authentication failures per user or per IP.
    • RBAC denial spikes.
    • GuardDuty high / critical findings.
    • KMS policy edits, IAM policy edits, CloudTrail config edits, Object Lock config edits.
    • Unexpected egress from Lambda to unknown destinations.
  2. Alerts route via EventBridge → SNS → on-call (email + phone).
  3. P0/P1 alerts are acknowledged within SLA; unacknowledged alerts escalate to CEO.

7. Access to logs

  1. Read access is limited to the Security Officer, on-call engineer, and (read-only, time-boxed) approved investigators.
  2. Every access to raw logs is itself logged; reading log data produces an audit entry.
  3. Engineers do not have delete or modify access to logs in any environment.

8. Admin visibility

  1. /admin/audit exposes the application audit log with filters and a verification control that walks the hash chain.
  2. /admin/security summarizes alerting state, unacknowledged findings, and recent privileged actions.

9. Roles & responsibilities

Role Responsibility
Security Officer Owns logging configuration and alerting rules.
Engineering Instruments applications; respects the allow-list.
On-call Acknowledges and triages alerts in SLA.

10. References

  • 012-incident-response-plan.md
  • 009-data-classification-and-handling-policy.md
  • 005-backup-and-recovery-policy.md

11. Revision history

Version Date Author Approver Change
1.0 2026-04-17 S.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center