unified

UC-LOG-04 — Continuously monitor systems for anomalous activity

Operate continuous monitoring under a documented strategy that defines what is monitored, the metrics, and the frequencies — including ongoing assessment of security-control effectiveness — and report security status to defined roles on a defined cadence. Deploy monitoring across hosts, networks, and applications, at the perimeter and interior, to detect attacks, indicators of compromise, unauthorized connections, and anomalous behaviour indicative of malicious acts, natural disasters, or errors. Analyze flagged anomalies promptly to determine whether they represent security events requiring further evaluation.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Logging, Monitoring & Detection
type
detective
category
technical

Details

unified_id
UC-LOG-04
title
Continuously monitor systems for anomalous activity
statement
Operate continuous monitoring under a documented strategy that defines what is monitored, the metrics, and the frequencies — including ongoing assessment of security-control effectiveness — and report security status to defined roles on a defined cadence. Deploy monitoring across hosts, networks, and applications, at the perimeter and interior, to detect attacks, indicators of compromise, unauthorized connections, and anomalous behaviour indicative of malicious acts, natural disasters, or errors. Analyze flagged anomalies promptly to determine whether they represent security events requiring further evaluation.
domain
Logging, Monitoring & Detection
control_type
detective
control_category
technical
members
  • framework
    nist-800-53
    control_id
    CA-7
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    SI-4
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.16
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC7.2
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    DE.CM-01
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections