unified
UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents
Systems generate log records that are protected and made available for continuous monitoring. Performance, capacity, and security events are monitored against thresholds, with alerts triaged and incidents identified and resolved through a tracked process. Resource use is projected and tuned to meet current and future capacity requirements.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Logging, Monitoring & Detection
- type
- detective
- category
- technical
Details
- unified_id
- UC-ACCESS-18
- title
- Log and monitor system activity, capacity, and incidents
- statement
- Systems generate log records that are protected and made available for continuous monitoring. Performance, capacity, and security events are monitored against thresholds, with alerts triaged and incidents identified and resolved through a tracked process. Resource use is projected and tuned to meet current and future capacity requirements.
- domain
- Logging, Monitoring & Detection
- control_type
- detective
- control_category
- technical
- members
- framework
- nist-csf-2
- control_id
- PR.PS-04
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.6
- coverage
- full
- relationship
- superset_of
- framework
- soc1
- control_id
- SOC1-11
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents
- UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents mitigates Missing or insufficient logging and audit trails
- strength
- primary
- rationale
- Systems generate protected log records made available for continuous monitoring, directly remedying absent/insufficient audit trails.
- UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents mitigates User error and mishandling of sensitive information
- strength
- related
- rationale
- Incident identification and capacity/performance monitoring surface error- and misconfiguration-driven incidents, enabling correction that limits impact.
- Production Operations & Processing Integrity Cycle operates UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents
- UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents maps_to A.8.6 — Capacity management
- framework
- iso-27001
- control_id
- A.8.6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents
- UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents mitigates No security monitoring or supervision of privileged activity
- strength
- primary
- rationale
- Continuously monitors security events against thresholds with alert triage and tracked incident resolution, filling the no-monitoring gap.
- UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents mitigates IT resilience failure — unplanned outage, data loss, slow recovery
- strength
- primary
- rationale
- Monitors performance/capacity against thresholds and projects/tunes resource use, directly reducing capacity-driven outages; incident tracking shortens recovery.
- UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents maps_to SOC1-11 — System monitoring and incident management — controls provide reasonable assurance that system performance, security events, and incidents are monitored, identified, and resolved.
- framework
- soc1
- control_id
- SOC1-11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- SSAE 18 (current AICPA SOC suite)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents maps_to PR.PS-04 — Platform Security: Log records are generated and made available for continuous monitoring
- framework
- nist-csf-2
- control_id
- PR.PS-04
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- Security-event monitoring with alert triage contributes to detecting attacks, though specialized detection sits in dedicated SIEM/IDS controls.