vStream Digital Media

Log Management Policy

1. Definitions

Log: A record of an event, action, or transaction that occurred within an information system, application, or network device. Logs provide an audit trail for security monitoring, troubleshooting, and compliance purposes.

Audit Trail: A chronological record that provides documentary evidence of the sequence of activities affecting a specific operation, procedure, or event. In ShineVR, this includes all content and data changes.

Security Event: Any occurrence that could indicate a potential security incident, policy violation, or threat to information assets, including failed login attempts, unauthorised access attempts, and configuration changes.

Google Cloud Logging: Google Cloud Platform's centralised logging service that collects, stores, and analyses logs from all GCP resources, applications, and services.

Cloud Audit Logs: Google Cloud Platform's audit logging that records who did what, when, and where within the GCP environment, including Admin Activity, Data Access, System Event, and Policy Denied logs.

Security Command Centre: Google Cloud Platform's security and risk management platform that provides centralised visibility, threat detection, and compliance monitoring across the entire GCP environment.

TermDefinition/Detail
LogA record of an event, action, or transaction that occurred within an information system, application, or network device.Logs provide an audit trail for security monitoring, troubleshooting, and compliance purposes.
Audit TrailA chronological record that provides documentary evidence of the sequence of activities affecting a specific operation, procedure, or event.In ShineVR, this includes all content and data changes.
Security EventAny occurrence that could indicate a potential security incident, policy violation, or threat to information assets, including failed login attempts, unauthorised access attempts, and configuration changes.
Google Cloud LoggingGoogle Cloud Platform's centralised logging service that collects, stores, and analyses logs from all GCP resources, applications, and services.
Cloud Audit LogsGoogle Cloud Platform's audit logging that records who did what, when, and where within the GCP environment, including Admin Activity, Data Access, System Event, and Policy Denied logs.
Security Command CentreGoogle Cloud Platform's security and risk management platform that provides centralised visibility, threat detection, and compliance monitoring across the entire GCP environment.

2. Policy Statement

vStream Digital Media maintains comprehensive logging and monitoring of all systems, applications, and infrastructure to support security incident detection, investigation, compliance requirements, and operational troubleshooting. This policy establishes requirements for log generation, collection, retention, protection, and analysis across all vStream systems, with particular attention to ShineVR application activities and Google Cloud Platform infrastructure.

All systems must generate appropriate logs, and all personnel must cooperate with log analysis activities. Tampering with, disabling, or circumventing logging mechanisms is strictly prohibited and may result in disciplinary action.

Logs are treated as sensitive information assets and must be protected with appropriate access controls and encryption. Log data may contain personal information and must be handled in compliance with GDPR requirements.

3. Purpose

The purpose of this policy is to:

4. Scope

This policy applies to:

5. Logging Requirements

5.1 Google Cloud Logging Infrastructure

vStream utilises Google Cloud Platform's centralised logging infrastructure:

5.2 Cloud Audit Logs

Google Cloud Audit Logs provide comprehensive audit trails of all activities within the GCP environment:

5.3 ShineVR Application Audit Trails

The ShineVR application maintains detailed audit trails for all content and data operations:

5.4 Security Event Logging

Critical security events are logged with enhanced detail:

5.5 Application and System Logs

Standard operational logging includes:

6. Security Command Centre Monitoring

vStream utilises Google Cloud Security Command Centre for continuous security monitoring and compliance:

6.1 Compliance Standards Monitoring

Security Command Centre monitors 19 compliance standards including:

6.2 Automated Detection and Alerting

Security Command Centre provides:

6.3 Review and Remediation

7. Automated Testing and Access Monitoring

vStream maintains over 400 automated tests that generate logs for security monitoring:

8. Log Retention

8.1 Retention Periods

Log retention periods are based on log type and regulatory requirements:

8.2 Log Storage and Protection

9. Log Analysis and Monitoring

9.1 Continuous Monitoring

9.2 Regular Reviews

10. Integration with Incident Response

Log management is closely integrated with vStream's Incident Response Plan:

11. Roles and Responsibilities

11.1 Chief Technology Officer

11.2 Backend Developers

11.3 All Employees

12. Privacy Considerations

Log data may contain personal information and must be handled in compliance with GDPR:

13. Related Policies and Documents

14. Contact Information

Data Protection Officer / Chief Technology Officer:

Andrés Pitt

Email: andres@vstream.ie

Phone: (086) 788 6570

Available 24/7 for P1 security incidents

Company Address:

vStream Digital Media

37 Leeson Close

Dublin 2, D02 H344

Ireland

Website: vstream.ie