Datadog logging & audit security checks
Audit logs, event retention and incident-response hooks — the evidence you need when something goes wrong, and the controls auditors ask for first.
On Datadog, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Datadog connector needs.
Checks (3)
severity: high Audit Logging Disabled fix difficulty: easy #
Enable Audit Trail to capture user activity and configuration changes
- Navigate to Organization Settings > Audit Trail
- Toggle "Enable Audit Trail" to on
- Configure the retention period as required by policy
- Optionally configure forwarding to a SIEM or log management system
- Save and verify audit events begin appearing in the trail
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-312.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1
severity: medium Audit Log Retention Period fix difficulty: easy #
Increase audit log retention to at least 90 days
- Navigate to Organization Settings > Audit Trail
- Ensure Audit Trail is enabled
- Locate the retention period setting
- Set the retention period to 90 days or greater as required by policy
- Save the configuration
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-08 NIST CSF 2.0 DE.CM GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1
severity: high Audit Retention Below Critical Threshold fix difficulty: easy #
Increase audit log retention to at least 30 days to meet the minimum regulatory floor
- Navigate to Organization Settings > Audit Trail
- Ensure Audit Trail is enabled
- Locate the retention period setting
- Set the retention period to at least 30 days (90+ days recommended for most compliance frameworks)
- Save the configuration
- Review your applicable compliance requirements (SOC 2, ISO 27001, PCI DSS) and increase retention accordingly
Satisfies: ISO 27001:2022 A.8.15 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.b.2 DORA (SaaS Security) DORA-10.1