unified
UC-BCDR-13 — Operate continuous security protection services
Operate ongoing protection services, including malware defense, network and endpoint security, and security monitoring, so that attacks and disruptions do not compromise service availability or data. Review and tune these services regularly to keep security risk within accepted levels.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Logging, Monitoring & Detection
- type
- preventive
- category
- technical
Details
- unified_id
- UC-BCDR-13
- title
- Operate continuous security protection services
- statement
- Operate ongoing protection services, including malware defense, network and endpoint security, and security monitoring, so that attacks and disruptions do not compromise service availability or data. Review and tune these services regularly to keep security risk within accepted levels.
- domain
- Logging, Monitoring & Detection
- control_type
- preventive
- control_category
- technical
- members
- framework
- cobit-2019
- control_id
- DSS05
- coverage
- partial
- delta
- also identity/logical access, physical access, and sensitive-document/output-device controls
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- Cybersecurity Assurance Review tests UC-BCDR-13 — Operate continuous security protection services
- UC-BCDR-13 — Operate continuous security protection services mitigates Coordinated multi-stage / APT campaigns
- strength
- primary
- rationale
- Endpoint/network protection plus security monitoring block malware and lateral movement across multi-stage campaigns.
- Security Control Assessment & POA&M Remediation tests UC-BCDR-13 — Operate continuous security protection services
- UC-BCDR-13 — Operate continuous security protection services mitigates Attacks by capable, motivated threat actors
- strength
- primary
- rationale
- Operating malware defense and network/endpoint security is a first-order preventive defense that stops attacks from succeeding.
- UC-BCDR-13 — Operate continuous security protection services maps_to DSS05 — Managed Security Services
- framework
- cobit-2019
- control_id
- DSS05
- coverage
- partial
- delta
- also identity/logical access, physical access, and sensitive-document/output-device controls
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-BCDR-13 — Operate continuous security protection services mitigates Adversary reconnaissance and information gathering
- strength
- related
- rationale
- Network/perimeter protection limits the scanning and probing adversaries use to map the environment.
- Security Monitoring & Detection Operations operates UC-BCDR-13 — Operate continuous security protection services
- UC-BCDR-13 — Operate continuous security protection services mitigates Data exfiltration and theft of information by attackers
- strength
- primary
- rationale
- Malware and network defenses directly counter the malware and sniffers adversaries install to locate and exfiltrate data.
- UC-BCDR-13 — Operate continuous security protection services mitigates No security monitoring or supervision of privileged activity
- strength
- related
- rationale
- The protection-services bundle includes ongoing security monitoring, contributing baseline monitoring coverage.