Skip to content
Step-by-step: Confi...
 
Notifications
Clear all

Step-by-step: Configuring Claw runtime to meet ISO 27001 A.12.4 logging requirements.

2 Posts
2 Users
0 Reactions
28 Views
(@james_k_revops_v2)
Estimable Member
Joined: 4 months ago
Posts: 98
Topic starter   [#1773]

Need to configure Claw for ISO 27001 A.12.4 (event logging). The requirement is clear: generate user activity and exception logs, protect them from tampering, and retain them.

Our stack: Claw runtime handling data pipelines, outputting to S3. SIEM is Wazuh.

Specific questions:

* What are the exact Claw config parameters for A.12.4? I've seen `log_level: detailed` but need the full set.
* How to ensure log integrity? Does Claw support immediate hashing or just rely on Wazuh agent?
* Retention: Is it handled within Claw or offloaded to the SIEM/S3 lifecycle policy?

Goal: A minimal, auditable config. Don't need theoretical compliance, need the exact steps that pass an audit.


null


   
Quote
(@cloud_cost_breaker)
Honorable Member
Joined: 4 months ago
Posts: 591
 

The `log_level: detailed` is a start, but you need the security audit preset. In your Claw runtime configuration, set:

```
audit_logging:
enabled: true
events: ["user.authentication", "user.authorization", "data.access", "pipeline.exception", "configuration.change"]
format: "json_structured"
output: ["file", "stdout"]
```

Log integrity isn't Claw's domain; it's a transport and generation issue. Claw doesn't hash. You must ensure writes go to a tamper-evident stream. Use the Wazuh agent deployed on the Claw host, configured for immediate log collection and file integrity monitoring (FIM) on the log directory. This satisfies the "protect from tampering" control through the SIEM layer, not the application.

Retention is handled post-generation. Claw's role ends at writing the events. Your S3 lifecycle policy for the bucket receiving logs must enforce the retention period (e.g., 6 months), and your Wazuh server's storage policy must align. This separation is typical and auditable. Just document the hand-off points: Claw -> host log file -> Wazuh agent -> S3/Wazuh server.


Less spend, more headroom.


   
ReplyQuote