---
name: framework-financial-services-shared-logging-audit-provider
title: Audit logging of application provider events and SIEM
description: In addition, to audit logging of IBM Cloud events, you also need to consider auditing of events your applications might generate. Auditable events from all sources need to be consolidated into a security information and event management (SIEM) system.
last-updated: 2025-03-02
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/framework-financial-services?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Audit logging of application provider events and SIEM
{: #shared-logging-audit-provider}

In addition, to [audit logging of IBM Cloud events](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-shared-logging-audit&format=markdown), you also need to consider auditing of events your applications might generate. Auditable events from all sources need to be consolidated into a security information and event management (SIEM) system.
{: shortdesc}

## Auditable events
{: #events}

You should audit the following events that occur within the system (in all environments, such as dev, test, prod):

* Access, downloading, revisions to Confidential information
* Access to or update to any financial transaction data
* Any changes to customer accounts
* Login or logoff event, success or failure
* Changes to a system that impact business logic or work flow, examples include but are not limited to, changing call routing, interest rates that are offered for a class of customer, a website flow a customer uses
* Any changes to customer systems that include but not limited to: software install or uninstall, configuration changes, directory or file moves, adds, or deletes, configuration changes, port turn ups, MAC’s, routing changes, and so on.
* Each command action taken, both successful and unsuccessful, by a privileged account that includes but not limited to:
    * All changes, additions, or deletions to any account such as lock, unlock, password reset, permission changes,
    * Modification to system time / time-synchronization configuration,
    * Log files: access to logs files; initialization, stopping or pausing of logging, log modification, changes to access permission on log files,
    * Files and system level objects creation and deletion,
    * Attempts to perform unauthorized functions or access data that the user is not authorized to access,
    * Modification of security rules,
    * Application and related systems start-ups and shut-downs
* For privileged accounts:
    * Attempts to execute privilege elevation
    * System errors relevant to security events, including but not limited to SQL errors that indicate an SQL injection, fuzzing, multiple failed logins, failed configuration change, failed/disabled anti-virus software, service failures
    * Web access events in extended log format

The events that are collected should comply with the Cloud Auditing Data Federation (CADF) standard. And, audit events must contain at a minimum:

* Type of event
* When the event occurred
* Where the event occurred
* Source of the event
* Outcome (success or failure) of the event
* Identity of any user/subject/device associated with the event
* Port and protocol, where available
* Session duration, identification, and modification where available
* Authentication method

## Storing events in a SIEM
{: #siem}

A SIEM system provides the ability to gather security data from information system components and presents that data as actionable information through a single interface. Events of the type in the previous section should be stored in a SIEM. You need to install your own software solution within your VPC for SIEM.

## Related IBM Cloud for Financial Services controls
{: #related-controls}

{{site.data.content.related-controls-disclaimer}}

| Family              | Control                                           |
|---------------------|---------------------------------------------------|
| Access Control (AC) | [AC-2 Account Management](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-2&format=markdown) \n [AC-2 (1) Account Management &#124; Automated System Account Management](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-2.1&format=markdown) \n [AC-2 (4) Account Management &#124; Automated Audit Actions](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-2.4&format=markdown) \n [AC-2 (7) Account Management &#124; Privileged User Accounts](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-2.7&format=markdown) |
| Audit and Accountability (AU) | [AU-3 Content of Audit Records](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-3&format=markdown) \n [AU-4 Audit Log Storage Capacity](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-4&format=markdown) \n [AU-5 Response to Audit Logging Process Failures](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-5&format=markdown) \n [AU-6 Audit Record Review, Analysis, and Reporting](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-6&format=markdown) \n [AU-6 (1) Audit Record Review, Analysis, and Reporting &#124; Automated Process Integration](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-6.1&format=markdown) \n [AU-7 Audit Record Reduction and Report Generation](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-7&format=markdown) \n [AU-10 Non-repudiation](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-10&format=markdown) \n [AU-11 Audit Record Retention](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-11&format=markdown) |
{: caption="Related controls in IBM Cloud Framework for Financial Services [FSv2.0]" caption-side="top"}
{: #related-controls-fsv2.0}
{: tab-title="FSv2.0"}
{: tab-group="RelatedControls-1"}
{: class="simple-tab-table"}


| Family              | Control                                           |
|---------------------|---------------------------------------------------|
| Access Control (AC) | [AC-2 Account Management](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-2&format=markdown) \n [AC-2 (1) Account Management &#124; Automated System Account Management](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-2.1&format=markdown) \n [AC-2 (4) Account Management &#124; Automated Audit Actions](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-2.4&format=markdown) \n [AC-2 (7) Account Management &#124; Privileged User Accounts](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-2.7&format=markdown) |
| Audit and Accountability (AU) | [AU-3 Content of Audit Records](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-3&format=markdown) \n [AU-4 Audit Log Storage Capacity](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-4&format=markdown) \n [AU-5 Response to Audit Processing Failures](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-5&format=markdown) \n [AU-6 Audit Record Review, Analysis. and Reporting](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-6&format=markdown) \n [AU-6 (1) Audit Record Review, Analysis. and Reporting &#124; Automated Process Integration](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-6.1&format=markdown) \n [AU-7 Audit Record Reduction and Report Generation](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-7&format=markdown) \n [AU-10 Non-repudiation](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-10&format=markdown) \n [AU-11 Audit Record Retention](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-11&format=markdown) |
{: caption="Related controls in IBM Cloud Framework for Financial Services [FSv1.1]" caption-side="top"}
{: #related-controls-fsv1.1}
{: tab-title="FSv1.1"}
{: tab-group="RelatedControls-1"}
{: class="simple-tab-table"}


## Next steps
{: #next-steps}

* [Operational logging](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-shared-logging-operational&format=markdown)