How can ManageEngine support organizations in meeting GAMP 5 standards?
With ManageEngine Log360 (SIEM), organizations can start aligning with the principles of GAMP 5. See the key clauses and how our solutions help in the table below.
Appendix 1: Handover Ensure a controlled transfer of the computerized system from project to operational use, with all required procedures, training records, and operational readiness checks in place before go-live.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Verify all SOPs, user roles, and access controls are operational before go-live.
- Capture a baseline of system configuration and user privileges.
- Ensure logging and monitoring are enabled from day one.
- Retain handover evidence for audit.
- Centralized log collection from more than 750 sources begins at go-live, providing a verifiable audit baseline.
- ADAudit Plus captures the initial AD configuration, GPO, and user/role baseline.
- Configuration change auditing flags any deviation from the approved handover state.
- Real-time alerts confirm logging pipelines are healthy from the initial stage.
- Local Account Management (User Account Created / Modified / Enabled)
- Group Management → Members added to Security group
- GPO Changes → GPO Created / Modified / Deleted
- Program Inventory → Software Installed / Software Updated
- Policy Changes → System Audit Policy Changes
- Local User Creation
- Net.exe User Account Creation
- Suspicious Windows ANONYMOUS LOGON Local Account Created
- Active Directory User Backdoors
- Audit Policy Changed
Appendix 2: Establishing and Managing Support Services Establish and manage support services (help desk, vendor support, SLAs) for the operational system, including monitoring of service performance.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Define support roles and SLAs.
- Track support tickets and resolution times.
- Monitor support-account activity.
- Audit third-party / vendor remote access.
- Integration with ServiceDesk Plus, ServiceNow, Jira, Zendesk for ticket correlation with security events.
- Privileged-user session monitoring for support and vendor accounts.
- VPN, RDP, and remote-access auditing.
- Workflow automation triggers tickets on incidents.
- SDP → Debug Reports: Successful Logins / Failed Logins
- Terminal Server Gateway Logons → Successful user connections to the resource / Failed connection authorizations
- Windows Logon Reports → Remote Interactive Logon / Remote Desktop Services Activity
- Windows Sessions → Remote Interactive Sessions / PMP Sessions
- Cisco/Fortinet/PaloAlto VPN Logon Reports → VPN Logons / Failed VPN Logons
- Admin User Remote Logon(Valid Accounts)
- Interactive Logon to Server Systems (Valid Accounts)
- Suspicious PsExec Execution(Remote Services)
- RDP Login from Localhost(Remote Services)
- Failed Logon From Public IP(External Remote Services)
Appendix 3: Performance Monitoring Continuously monitor system performance, availability, and capacity to ensure the system remains fit for intended use.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Monitor server, application, and network performance KPIs.
- Detect availability issues proactively.
- Trend capacity over time.
- Alert on performance anomalies.
- EventLog Analyzer monitors Windows/Linux/Unix server performance and service health.
- Application log analytics for IIS, Apache, SQL, Oracle, etc.
- Real-time alerts on service stops, high CPU/memory, disk thresholds.
- Custom dashboards for availability KPIs.
- Windows System Events → Low Disk Space / Hard disk failures
- Windows Startup Events → System Uptime / UnExpected Shutdown
- Service Audit → Service Stopped / Service Failed
- MSSQL Advanced Auditing Reports → Waits Information Report / Blocked Processes Report
- Device Severity Reports → Critical Events / Error Events
- DoS Attacks / DoS Attack Entered Defensive Mode(Threat Detection)
- Stop Windows Service(Service Stop)
- Microsoft Malware Protection Engine Crash(Exploitation for Defense Evasion)
- Hyper-V Disk Out of Space(Hyper-V VM Management)
- Blue Screen Error (BSOD)(Application Crashes)
Appendix 4: Incident Management All incidents impacting the system shall be recorded, classified, investigated, resolved, and reviewed for root cause.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Detect and log every security/operational incident.
- Classify by severity and impact.
- Track investigation and closure.
- Preserve forensic evidence.
- Vigil IQ correlation engine detects incidents across data sources in real time.
- Built-in incident-management console with assignment, status, and audit trail.
- Forensic search with timestamped, tamper-evident archives.
- MITRE ATT&CK® -aligned alert context for triage.
- Windows Eventlog Reports → Security Logs Cleared / Event Logs Cleared
- Windows Important Events → Audit Logs Cleared / Audit Policy Changed
- Failed Logon Reports → Top reasons for windows logon failure / Failed Logons Trend
- Threat Detection From Antivirus → Defender Malware Detection / Threat Detections by McAfee
- Sophos HeartBeat Status → Endpoint Risk Report / Endpoint Warning Report
- Eventlog Cleared / Security Eventlog Cleared (Indicator Removal on Host)
- Suspicious Eventlog Clear or Configuration Using Wevtutil (Indicator Removal on Host)
- Account Tampering – Suspicious Failed Logon Reasons (Valid Accounts)
- Maze Ransomware (User Execution)
- NotPetya Ransomware Activity (Indicator Removal on Host)
Appendix 5: Corrective and Preventive Action (CAPA) Implement CAPA processes triggered by incidents, deviations, or audit findings; verify effectiveness of actions taken.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Link CAPAs to source incidents.
- Track action owners and due dates.
- Verify recurrence does not happen.
- Document evidence of effectiveness.
- Automated workflows execute predefined response actions (disable user, isolate host, kill process).
- Repeat-incident detection reopens linked alerts to verify CAPA effectiveness.
- Audit trail of every workflow execution stored immutably.
- Nessus Vulnerability Reports → Patch Report / Top Exploitable Vulnerabilities
- Qualys Reports → Confirmed vulnerabilities / Severe Vulnerabilities
- Program Inventory → Windows Updates - Installed / Windows update process failed
- Policy Changes → System Audit Policy Changes / Domain Policy Changes
- Trend Reports → Weekly Report / Hourly Report
- NotPetya Ransomware Activity(Indicator Removal on Host)
- Maze Ransomware(User Execution)
- Possible Ransomware or Unauthorized MBR Modifications(Pre‑OS Boot)
- Suspicious Reconnaissance Activity(Account Discovery)
- Disabling Windows Event Auditing (Impair Defenses)
Appendix 6: Operational Change & Configuration Management All changes to the validated system shall be assessed, approved, documented, implemented, and reviewed under formal change control; configuration baselines shall be maintained.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Detect every configuration change in real time.
- Match changes to approved CRs.
- Maintain a configuration baseline.
- Roll back unauthorized changes.
- ADAudit Plus tracks every AD object, GPO, schema, and OU change with before/after values.
- Server configuration auditing (registry, file, service, scheduled task).
- Network device configuration change tracking (firewall, router, switch).
- Alerts on changes outside approved windows.
- Registry Changes → Registry Value Modified / Registry Permission Changes
- GPO Changes → GPO Modified
- Windows Firewall Auditing → Windows Firewall Rule Added / Modified / Deleted
- Service Audit → New Service Installed / Service Stopped
- MSSQL DDL Auditing → Schemas Altered / Tables Altered
- Direct Autorun Keys Modification
- Suspicious Service Path Modification
- New Service Creation
- Disabling Windows Event Auditing
- COMPlus_ETWEnabled Registry Modification.
Appendix 7: Repair Activity Repairs shall be performed by qualified personnel under controlled conditions and documented; system shall be reverified before return to use.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Restrict repair to authorized engineers.
- Capture all actions taken during repair.
- Reverify configuration post-repair.
- Retain evidence of work.
- Privileged session recording context (who/when/where for repair logons).
- File-integrity monitoring rebaselines after repair.
- Configuration drift reports compare pre/post-repair state.
- Service Audit → New Service Installed / Service Failed
- System Events → Failed loadings of Kernel driver / Code Integrity Check
- Windows Backup and Restore → Successful Windows restores / Failed Windows restores
- Registry Changes → Registry Value Modified / Registry Permission Changes
- Program Inventory → Software Installed / Failed software installations
- New Service Creation(Create or Modify System Process)
- Suspicious Service Path Modification(Create or Modify System Process)
- Malicious Service Installations(Create or Modify System Process)
- Failed Code Integrity Checks(Obfuscated Files or Information)
- Suspicious Driver Loaded By User (Impair Defenses)
Appendix 8: Periodic Review The system shall be periodically reviewed to confirm it remains in a validated, compliant state and continues to meet its intended use.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Schedule periodic reviews (annually or risk-based).
- Review access rights, incidents, changes, deviations.
- Document review outcome and actions.
- Scheduled compliance and access reports auto-delivered to reviewers.
- User access review dashboards (inactive users, stale privileges).
- Trend dashboards for incidents, changes, and policy violations across the period.
- Logon Reports → Top Logons by User / Logons Trend
- Local Account Management → User Accounts Created With no password expiry
- Domain Controller Logon Reports → DC Credentials Validation Success
- Policy Changes → User Rights Assigned / User Rights Removed
- Trend Reports → Weekly Report
- AD Privileged Users or Groups Reconnaissance
- Admin User Remote Logon
- Enabled User Right in AD to Control User Objects
- Interactive Logon to Server Systems
- User Added to Local Administrators
Appendix 9: Backup and Restore Adequate, tested backup and restore procedures shall be in place to ensure data and system recovery; backup activity and integrity shall be monitored.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Verify backup jobs run successfully.
- Detect failed/missed backups.
- Audit restore operations.
- Protect backup integrity.
- Audits backup software events (Veeam, NetBackup, Veritas, Windows Backup, etc.).
- Alerts on failed/missed backup jobs.
- Logs all restore operations and who performed them.
- Detects deletion or tampering of backup files.
- Windows Backup and Restore → Successful Windows backup / Failed Windows backup
- Windows Backup and Restore → Successful Windows restores / System Restored
- MSSQL Backup and Restore → Databases Backed Up / Database Backup Failed
- MSSQL Backup and Restore → Database Restore
- System Events → AD Backup Error
- Backup Catalog Deleted
- Shadow Copies Deletion Using Operating Systems Utilities
- NotPetya Ransomware Activity
- Possible Ransomware or Unauthorized MBR Modifications
- Modification of Boot Configuration
Appendix 10: Business Continuity Management Business continuity and disaster recovery plans shall ensure system availability for critical regulated processes; plans shall be tested.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Maintain DR plan and test it.
- Monitor BCP-critical systems continuously.
- Detect events that could impact continuity.
- High-availability deployment of Log360 itself ensures monitoring continuity.
- DR drill-event correlation across primary and secondary sites.
- Real-time alerts on outages of business-critical services and links.
- Windows Startup Events → UnExpected Shutdown / Windows Restarts
- Service Audit → Service Failed / Service Stopped
- System Events → Hard disk failures / Low Disk Space
- Application Crashes → Blue Screen Error(BSOD)
- Threat Detection From Antivirus → Defender Malware Detection
- Maze Ransomware
- Stop Windows Service
- Shadow Copies Deletion Using Operating Systems Utilities Inhibit System Recovery – Modification of Boot Configuration
- Secure Deletion with SDelete
Appendix 11: Security Management Logical and physical security controls shall protect the system, data, and electronic records from unauthorized access, use, modification, or destruction. Security events shall be monitored.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Enforce least privilege.
- Detect intrusions and policy violations in real time.
- Monitor privileged access.
- Respond to threats automatically.
- Full SIEM with real-time correlation (Vigil IQ) and more than 2,000 detection rules.
- UEBA detects insider threats and compromised accounts via behavior baselining.
- Integrated threat-intel feeds (STIX/TAXII, Webroot) flag malicious IPs/URLs/domains.
- MITRE ATT&CK-aligned detection coverage.
- Automated response workflows (disable account, block IP, isolate host).
- Eventlog Reports → Security Logs Cleared / Event Logs Cleared
- Failed Logon Reports → Failed Logons Trend / Top reasons for windows logon failure
- Threat Detection → DoS Attacks / Replay Attack
- Windows Important Events → Audit Logs Cleared
- File Integrity Monitor → File Monitoring Overview
- Eventlog Cleared / Security Eventlog Cleared
- Suspicious Eventlog Clear or Configuration Using Wevtutil
- Metasploit SMB Authentication (Brute Force)
- Mimikatz Use / Mimikatz Command Line
- Possible Impacket SecretDump Remote Activity
Appendix 12: System Administration System administration activities (account management, patching, scheduled tasks, etc.) shall be controlled, segregated from end-user activity, and auditable.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Track all admin actions.
- Enforce SoD between admin and user roles.
- Audit account life cycle (create/modify/disable/delete).
- Monitor patch and scheduled-task changes.
- Comprehensive admin-action auditing across AD, Azure AD/Entra ID, Microsoft 365, Linux/Unix, databases, and network devices.
- Account life cycle reporting (creation, enable/disable, deletion, password reset).
- Scheduled-task and service-account change tracking.
- Patch and update event correlation.
- Local Account Management → User Account Created / User Account Modified
- Group Management → Members added to Security group / Security Group Changed
- GPO Changes → GPO Created / GPO Modified
- Policy Changes → User Rights Assigned / Authentication Policy Change (Grant)
- Process Tracking → Scheduled Task Created / Scheduled Task Updated
- User Added to Local Administrators(Valid Accounts)
- Suspicious Windows ANONYMOUS LOGON Local Account Created (Create Account)
- Active Directory User Backdoors(Account Manipulation)
- Addition of SID History to Active Directory Object (Access Token Manipulation)
- Password Change on Directory Service Restore Mode (DSRM) Account(Account Manipulation)
Appendix 13: Archiving and Retrieval Records (including electronic records and audit trails) shall be retained for the required period in a secure, retrievable, and tamper-evident form.
Compliance actions How Log360 helps Reports and evidences Threat rules
- Define retention period per record class.
- Protect archives from tampering.
- Ensure records remain retrievable and readable.
- Securely destroy when retention expires.
- Encrypted, hash-stamped, tamper-evident log archives.
- Configurable retention per log source / regulation.
- Fast forensic search across archived data.
- Role-based access to archived records.
- Windows Backup and Restore → Successful windows backup / Failed Windows backup
- MSSQL Backup and Restore Events → Databases Backed Up / Database Backup Failed
- Eventlog Reports → Event log automatic backup / Security Log Full
- File Integrity Monitor → File (or) Folder Modified / Folder Permission Changes
- Eventlog Reports → Security Logs Cleared / Event Logs Cleared
- Backup Catalog Deleted(Indicator Removal on Host)
- Shadow Copies Deletion Using Operating Systems Utilities (Inhibit System Recovery)
- Secure Deletion with SDelete(Indicator Removal on Host)
- Eventlog Cleared / Security Eventlog Cleared(Indicator Removal on Host)
- Modification of Boot Configuration(Inhibit System Recovery)



