Skip to content

Datadog logging & audit security checks

Audit logs, event retention and incident-response hooks — the evidence you need when something goes wrong, and the controls auditors ask for first.

On Datadog, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Datadog connector needs.

Checks (3)

severity: high Audit Logging Disabled fix difficulty: easy #

Enable Audit Trail to capture user activity and configuration changes

  1. Navigate to Organization Settings > Audit Trail
  2. Toggle "Enable Audit Trail" to on
  3. Configure the retention period as required by policy
  4. Optionally configure forwarding to a SIEM or log management system
  5. Save and verify audit events begin appearing in the trail

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: medium Audit Log Retention Period fix difficulty: easy #

Increase audit log retention to at least 90 days

  1. Navigate to Organization Settings > Audit Trail
  2. Ensure Audit Trail is enabled
  3. Locate the retention period setting
  4. Set the retention period to 90 days or greater as required by policy
  5. Save the configuration

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

severity: high Audit Retention Below Critical Threshold fix difficulty: easy #

Increase audit log retention to at least 30 days to meet the minimum regulatory floor

  1. Navigate to Organization Settings > Audit Trail
  2. Ensure Audit Trail is enabled
  3. Locate the retention period setting
  4. Set the retention period to at least 30 days (90+ days recommended for most compliance frameworks)
  5. Save the configuration
  6. Review your applicable compliance requirements (SOC 2, ISO 27001, PCI DSS) and increase retention accordingly

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.15 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1

More Datadog checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial