Information Security Policy

System Monitoring and Logging Policy

PART I - PURPOSE, SCOPE, AND LEGAL BASIS

Article 1. Purpose

1.1. This Policy governs logging, monitoring and alerting across all HiTechCloud systems, in order to: (a) detect incidents and anomalous behavior early; (b) support investigation, incident response and forensic tracing; (c) demonstrate accountability and legal compliance; and (d) preserve the integrity and availability of digital evidence.

Article 2. Scope of application

2.1. Applies to: servers, workstations, network devices and firewalls; web applications, APIs and databases; authentication and access control systems (IAM/PAM); cloud infrastructure, containers and orchestration; security systems (WAF, IDS/IPS, EDR/XDR); and the Customer management portal.

Article 3. Legal basis and standards

  • Law on Cybersecurity 2025 (Law No. 116/2025/QH15) and its implementing decrees; Decree 85/2016/ND-CP on securing information systems by classification level;
  • Decree 147/2024/ND-CP on the management, provision and use of internet services and online information (log retention requirement);
  • The Law on Personal Data Protection 2025 (Luật Bảo vệ dữ liệu cá nhân 2025, Law No. 91/2025/QH15) and Decree 356/2025/NĐ-CP (data processing logs; protection of personal data held in logs);
  • Penal Code 2015 (amended and supplemented 2017);
  • Reference standards: ISO/IEC 27001:2022 (A.8.15 logging, A.8.16 monitoring, A.8.17 clock synchronization); NIST SP 800-92 (log management); MITRE ATT&CK.

This policy supplements the Information Security Management System Policy (ISMS), the Access Control Policy (IAM) and the Incident Response Procedure (IR).


PART II – LOGGING

Article 4. Events that must be logged

4.1. HiTechCloud logs at minimum the following events: (a) authentication — successful and failed logins, account lockouts, password changes, MFA authentication; (b) access control — granting and revoking rights, privilege escalation (sudo/su), access to sensitive resources; (c) administrative actions — configuration changes, account creation and deletion, security policy changes; (d) system events — service starts and stops, system errors and state changes; (e) security events — IDS/IPS/WAF/EDR alerts, malware detection and blocked connections; (f) data access — reading/writing/deleting CONFIDENTIAL/RESTRICTED data; (g) network activity — unusual inbound/outbound connections, firewall rule changes.

Article 5. Log record contents

5.1. Each log record contains at minimum: a timestamp (with time zone); the subject identifier (user or service ID); the source (IP or hostname); the event type and outcome (success/failure); the resource affected; and a correlation ID where one exists.

5.2. Data minimization principle: does not write unnecessary sensitive data to logs, such as passwords, secret keys, full tokens, full payment card numbers or the content of sensitive personal data. Where a personal identifier must be logged, appropriate masking or pseudonymization is applied in line with the PDPD.

Article 6. Time synchronization

6.1. All systems synchronize time against trusted internal NTP servers on UTC+07:00, so that log sources correlate accurately for investigations.


PART III - LOG PROTECTION, RETENTION, AND ACCESS

Article 7. Centralization and integrity

7.1. Logs are collected centrally into a log management/SIEM system, kept separate from the source systems to prevent tampering.

7.2. Integrity protection: apply anti-tampering mechanisms (append-only/WORM) and sign or hash records where required; enforce strict access control on the log store; all access to the logging system is itself logged (log-of-log).

Article 8. Retention period

Log typeMinimum retention period
System access and login logs12 months (in line with Decree 147/2024/NĐ-CP)
Security logs, security events12 months (hot) plus cold storage as investigations require
Admin logs, configuration changes12 months
Personal data processing logAs required for accountability under the PDPD and Decree 356/2025
Digital evidence for incident responseAt least 24 months after the incident closes (or as required by the competent authority)

8.1. Logs that reach the end of their retention period are securely destroyed and the destruction is recorded; logs relating to an ongoing investigation, or required by a competent authority, are retained until the matter is closed.

Article 9. Log access control

9.1. Access to logs follows the principle of least privilege under the Access Control (IAM) Policy; only SOC staff, security administrators and authorized investigators may access them; and every access is logged and reviewed.

9.2. Use of logs containing personal data complies with the PDPD; such logs are used only for security, operations, incident investigation and legal compliance purposes.


PART IV – MONITORING, ALERTING AND EFFECTIVE DATE

Article 10. Monitoring and event correlation

10.1. HiTechCloud operates a Security Operations Center (SOC) with SIEM that correlates events across multiple sources, and builds detection rules mapped to the MITRE ATT&CK framework to identify: anomalous logins by location or time, brute-force attempts, privilege escalation, bulk data access or downloads, command-and-control (C2) and exfiltration behavior, and unauthorized configuration changes.

10.2. Availability and performance monitoring (uptime, resource usage), aligned with the status.hitechcloud.vn status page and the commitments in the SLA.

Article 11. Alert classification and escalation

11.1. Alerts are classified by severity (Critical/High/Medium/Low), corresponding to P1–P4; critical alerts (P1/P2) are escalated immediately to the Computer Security Incident Response Team (CSIRT) under the Incident Response Procedure. Alerts involving a potential personal data breach simultaneously trigger the Data Breach Notification Procedure (72-hour threshold).

11.2. HiTechCloud monitors critical systems 24/7; thresholds and response procedures are configured according to the priority levels defined in the SLA and the incident response procedure.

Article 12. Review and improvement

12.1. The SOC periodically reviews the effectiveness of detection rules, reduces false positive alert noise and updates rules in line with new threat intelligence; monitoring reports are submitted to the Information Security Committee (ISC) each quarter.

Article 13. Effect

13.1. This policy takes effect from 01/07/2026 and is reviewed at least once every 12 months. The Vietnamese version prevails.

Revision history

Current versionby HiTechCloud
Updatedby HiTechCloud
Updatedby HiTechCloud
Updatedby HiTechCloud
Follow category: Information security policiesGet notified when new documents are added to this category.

If this article did not answer your question, please contact HiTechCloud for help.

Contact