Back to Blog
Hardware & Software

FortiGate Logging ISO 27001 Requirements (2026 Guide)

FortiGate Logging ISO 27001 Requirements (2026 Guide)
FortiGate logging for ISO 27001: which logs, retention, integrity, access rights, reviews, and SoA evidence—with a practical checklist.
Published
August 01, 2026
Updated
August 01, 2026
Reading Time
14 min read
Author
LeonX Expert Team

FortiGate logging ISO 27001 requirements define how traffic, event, and security logs on a FortiGate NGFW support ISMS monitoring, recording, and incident evidence. Short answer: enabling logs is not enough—you must define which events are recorded, where they are archived centrally, how long they are kept, who can access them, and how often they are reviewed. Compliance = log source + retention + access control + review + SoA.

This guide is written for:

  • IT/security teams preparing for ISO 27001 certification or surveillance audits
  • FortiGate operators answering SoA monitoring controls with technical evidence
  • SOC and ops teams running SIEM / FortiAnalyzer
  • Decision makers designing log evidence alongside Law No. 5651 and KVKK

Quick Summary

  • For ISO 27001, logging means produce + protect + review.
  • Minimum FortiGate package: critical policy logging, admin/event logs, central destination, NTP.
  • On-box disk logs are not an audit archive—plan retention on Analyzer/SIEM.
  • Log access needs separate rights; an archive everyone can delete is weak evidence.
  • Technical setup: How to Configure FortiGate Logging.
  • Network-control context: ISO 27001 Network Security with FortiGate.

Table of Contents

FortiGate logging ISO 27001 requirements

Image: Wikimedia Commons - WatchGuard Firebox 1000 (example enterprise firewall / log-source form factor).

What ISO 27001 Expects from Logging

ISO/IEC 27001 expects monitoring of events, protection of records, and an evidence chain for security incidents. FortiGate is a gateway log source: who went where via which policy, what admins changed, and who connected over VPN.

Short definition:

FortiGate logging ISO 27001 requirements means producing FortiGate records that match ISMS monitoring controls, storing them centrally, restricting access, and reviewing them on a schedule.

“Log & Report is open in the GUI” is not SoA evidence. Auditors typically want sample logs, a retention policy, an access list, and review records. Broader framing: ISO 27001 Network Security.

Requirements Map

ISO-oriented needFortiGate / architecture counterpartEvidence
Record critical accessLog allowed/denied on policiesPolicy export + sample traffic logs
Admin actionsEvent / admin login logsLogin + config-change samples
Central monitoringSyslog/SIEM or FortiAnalyzerDestination config + test record
Time integrityNTP + timezoneNTP status, offset <1–2 s
Retention periodCentral archive policyWritten retention (30–90 days+)
Log access controlSIEM/Analyzer RBACPrivilege matrix, audit trail
Periodic reviewReview calendarSigned report (90 days)

Policy–log link: Policy Configuration. Access-control evidence: FortiGate Access Control ISO 27001.

Which FortiGate Logs Are In Scope?

ISO does not mean “log everything”—it means scope aligned to risk and SoA:

  1. Traffic logs — critical allow/deny, server-zone access, post-VPN destinations
  2. Event logs — admin login, config change, system/HA events
  3. Security logs — IPS/AV/web filter (when licensed profiles are used)
  4. VPN / auth logs — remote-access identity and session records

Log types left out of scope need a risk justification. Setup steps: How to Configure FortiGate Logging. VPN side: SSL VPN Setup.

Pro Tip: Next to the “network device logs” SoA row, write the FortiGate hostname/serial and SIEM/Analyzer index name. The “which device?” audit question closes immediately.

Retention, Integrity, and Time

Retention follows institutional risk and legal duties. Practical split:

PurposeTypical duration (example)Where
Ops / troubleshooting30–90 daysSIEM hot tier
Audit / incident investigationpolicy-driven (months–years)warm/cold archive
Law No. 5651 (separate legal)multi-year (org policy)legal archive

On-box disks overwrite when full; long retention needs a central destination. For integrity:

  • Correct, monitored NTP
  • Log path on the management network / encrypted when possible
  • Separated delete rights on the central archive
  • Hash/WORM or SIEM immutability where feasible

SIEM architecture: SIEM, Syslog and 5651. Integrity angle: Log Integrity under 5651.

Access Rights and Review

For ISO, who can read or delete logs matters as much as producing them:

  • FortiGate admin ≠ SIEM admin (segregation of duties)
  • Deleting logs / changing retention needs separate approval
  • Written review cadence (e.g. weekly SOC + quarterly ISMS)
  • Alerts for deny spikes, admin fail logins, VPN anomalies

In HA, clarify which node emits logs: HA Setup.

ISO + 5651 + KVKK

FrameworkWhat it expects from logsFortiGate role
ISO 27001Monitoring, retention, review, incident evidenceTraffic/event/security source
Law No. 5651Internet-access records / evidenceNAT/traffic logs + identity layer
KVKKAccess trail for breach/investigationSegmentation + access logs

5651 ≠ ISO. The same FortiGate source can feed two policies, but purpose and retention must stay distinct: 5651 Logging, 5651 vs KVKK, KVKK Network Security with FortiGate.

Evidence Auditors Often Request

  1. Export showing log enabled on critical policy IDs
  2. Sample traffic + admin login from the last 7–30 days
  3. Central destination (syslog/Analyzer) config screenshot
  4. Retention policy PDF / procedure
  5. Log access privilege list
  6. Latest review report (date + approval)
  7. NTP status and timezone

Without this pack, “logging exists” is a weak claim.

Most Common Mistakes

  • Trusting Log & Report while policy logging is off
  • Expecting ISO retention from on-box disk alone
  • Missing or wrong NTP/timezone
  • Giving everyone SIEM delete rights
  • Calling automatic logs “compliance” without review
  • Treating a 5651 archive as ISO review evidence (different purpose)

Related Articles

Checklist

  • SoA defines FortiGate log scope (traffic/event/security).
  • Critical policies have log allowed/denied enabled.
  • Admin login and config changes hit event logs.
  • Central syslog/SIEM or FortiAnalyzer tested.
  • NTP offset monitored (<1–2 s).
  • Retention written; on-box disk is not the only archive.
  • Delete rights separated; RBAC documented.
  • Review calendar and latest report archived.
  • HA log source (active/passive) clarified.

Next Step with LeonX

FortiGate logging for ISO 27001 is an evidence chain—not the appliance alone. Under Hardware & Software Solutions, LeonX aligns FortiGate + central logging with ISMS expectations. See especially SIEM and Security Event Management Integration and Network Security, Firewall and IPS/IDS. For governance, use Network Security Policy Management and Contact.

Frequently Asked Questions

Is FortiGate logging enough for ISO 27001?

Not by itself. With central retention, access rights, a retention policy, reviews, and SoA, it contributes to ISO monitoring controls.

Which log types are mandatory?

The standard does not name models; risk and SoA decide. In practice, critical traffic, admin/event, and (if used) security logs form the minimum pack.

Is FortiAnalyzer required?

No—syslog/SIEM is acceptable. FortiAnalyzer eases native Fortinet reporting and needs a separate license.

How long should logs be kept?

Ops is often 30–90 days; audit/legal periods extend by policy. Write the duration down—do not rely on disk overwrite.

Does 5651 logging satisfy ISO?

No. The same source can feed both, but purpose, retention, and review processes differ.

Sources

Internal Link Path

Continue to the most relevant service pages

Use the links below to move from this article to the primary service, the most relevant detail page and the contact flow.

Share this article

Related Posts

Discover more on similar topics

How to Achieve ISO 27001 Network Security with FortiGate (2026)
Hardware & Software
2026-07-31
14 min read

How to Achieve ISO 27001 Network Security with FortiGate (2026)

Use FortiGate for ISO 27001 network security: segmentation, firewall policy, VPN, logging, admin hardening, and SoA evidence—with a practical checklist.

Read Article
KVKK-Compliant Network Security with FortiGate (2026 Guide)
Hardware & Software
2026-07-30
14 min read

KVKK-Compliant Network Security with FortiGate (2026 Guide)

How to use FortiGate for KVKK-aligned network security: segmentation, access control, VPN, logging, encryption balance, and a practical technical-controls checklist.

Read Article
How to Configure FortiGate Logging: Syslog, Disk, and FortiAnalyzer (2026)
Hardware & Software
2026-07-29
14 min read

How to Configure FortiGate Logging: Syslog, Disk, and FortiAnalyzer (2026)

How to set up FortiGate logging: traffic/event/security logs, disk vs syslog, FortiAnalyzer, retention, and practical settings for 5651/ISO 27001 evidence.

Read Article

Subscribe to Our Newsletter

Get the latest insights, trends, and expert advice delivered directly to your inbox. Join our community of IT professionals.

We respect your privacy. Unsubscribe at any time.