risk
No security monitoring or supervision of privileged activity
Absence of monitoring mechanisms and supervision of personnel actions (especially privileged users) allows undetected misuse, and no process exists to supervise and escalate detected security breaches.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Logging, Monitoring & Detection
- Incident Management & Response
- taxonomy
- iso-27005-vulnerability
- inherent_rating
- high
Details
- risk_id
- log-no-monitoring-supervision
- category
- cyber_security
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-vulnerability
Source
No record-specific source URL is provided.
Connections
- UC-IR-03 — Provide channels to report events and obtain response help mitigates No security monitoring or supervision of privileged activity
- strength
- related
- rationale
- All-personnel reporting of suspected events provides a human detection channel that partially compensates for absent monitoring of suspicious activity.
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates No security monitoring or supervision of privileged activity
- strength
- primary
- rationale
- Operating continuous monitoring across hosts, networks, and applications directly fills the absence-of-monitoring gap.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel mitigates No security monitoring or supervision of privileged activity
- strength
- primary
- rationale
- A central analysis capability that reviews records on cadence and routes findings to authorized staff supplies the missing monitoring and escalation.
- UC-IR-04 — Triage, categorize, and escalate reported security events mitigates No security monitoring or supervision of privileged activity
- strength
- related
- rationale
- Provides the documented process to supervise and escalate detected breaches to defined roles/tiers that the risk says is missing.
- UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents mitigates No security monitoring or supervision of privileged activity
- strength
- primary
- rationale
- Continuously monitors security events against thresholds with alert triage and tracked incident resolution, filling the no-monitoring gap.
- UC-LOG-07 — Monitor user sessions and personnel activity mitigates No security monitoring or supervision of privileged activity
- strength
- primary
- rationale
- Monitoring administrator and privileged/remote sessions for misuse directly supplies the supervision of privileged activity the risk describes as absent.
- UC-LOG-01 — Log security-relevant events across all systems mitigates No security monitoring or supervision of privileged activity
- strength
- related
- rationale
- Logging privileged actions is the prerequisite record that makes supervision of privileged activity possible.
- UC-LOG-06 — Evaluate events and declare incidents against defined criteria mitigates No security monitoring or supervision of privileged activity
- strength
- primary
- rationale
- Defined criteria to evaluate events, declare incidents, and initiate response supply the escalation process for detected breaches that was absent.
- UC-BCDR-13 — Operate continuous security protection services mitigates No security monitoring or supervision of privileged activity
- strength
- related
- rationale
- The protection-services bundle includes ongoing security monitoring, contributing baseline monitoring coverage.