In a recent LinkedIn post, Francisco Gaffney discusses the critical shortcomings in current logging and auditing practices that impede effective incident analysis and compliance, particularly under regulations like GDPR. Gaffney argues that the absence of essential details such as timestamps and ownership in log data creates significant obstacles for businesses striving for reliability and accountability.
The Challenge of Inadequate Logging
Francisco Gaffney points out that a fundamental issue lies in the lack of structured and informative logs. This deficiency not only complicates the analysis of security incidents but also creates hurdles for comprehensive audits. As Gaffney states:
“Logs lacking timestamps and owners hinder incident analysis and audits, impacting reliability.”
This lack of detail, Gaffney explains, makes it difficult to reconstruct events accurately, identify responsible parties, and verify the effectiveness of security controls. The implications extend beyond operational efficiency, directly impacting a company’s ability to meet regulatory requirements.
GDPR Compliance and Data Subject Rights
The impact of poor logging practices is particularly acute in the context of data privacy regulations like GDPR. Gaffney highlights that processors handling personal data have specific obligations under Article 28 of GDPR regarding information and audits. Without proper records, fulfilling these obligations becomes a complex and inefficient process.
According to Gaffney, this inefficiency directly affects the ability of individuals to exercise their data subject rights. He notes:
“Without structured records, exercising rights becomes inefficient, hindering compliance verification.”
This underscores the importance of robust logging not just for internal security and operations, but as a cornerstone of demonstrating compliance with privacy laws and respecting individual rights.
A Path to Continuous Compliance
Gaffney proposes that achieving continuous compliance and effective auditing requires a more structured and integrated approach. He outlines key components necessary for ongoing proof of control effectiveness, including a control catalog mapped to risks, routine control testing with evidence, continuous monitoring, independent assurance, and a regular review cadence.
However, Gaffney suggests there is a more streamlined and effective method. He advocates for a centralized system that provides continuous gap analysis and a clear overview of compliance status. As Francisco Gaffney puts it:
“All in one place. Continuous gap analysis. Clear view of what’s done, what’s missing, and who owns the fix before assurance or audit.”
This integrated approach, Gaffney argues, allows organizations to address compliance issues proactively and efficiently, ensuring that controls are not only documented but also actively managed and remediated. The ultimate goal, as he concludes, is to implement these processes correctly from the outset:
“Do it once. Do it properly. Move on.”
Gaffney’s insights emphasize the need for businesses to move beyond fragmented and reactive compliance efforts towards a more systematic and continuous approach, facilitated by better data management and integrated control frameworks.
📝 About This Content
This article is based on insights shared by Francisco Gaffney on LinkedIn.
📅 Originally posted on November 15, 2025 | View original post on LinkedIn →