unified
UC-LOG-04 — Continuously monitor systems for anomalous activity
Operate continuous monitoring under a documented strategy that defines what is monitored, the metrics, and the frequencies — including ongoing assessment of security-control effectiveness — and report security status to defined roles on a defined cadence. Deploy monitoring across hosts, networks, and applications, at the perimeter and interior, to detect attacks, indicators of compromise, unauthorized connections, and anomalous behaviour indicative of malicious acts, natural disasters, or errors. Analyze flagged anomalies promptly to determine whether they represent security events requiring further evaluation.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Logging, Monitoring & Detection
- type
- detective
- category
- technical
Details
- unified_id
- UC-LOG-04
- title
- Continuously monitor systems for anomalous activity
- statement
- Operate continuous monitoring under a documented strategy that defines what is monitored, the metrics, and the frequencies — including ongoing assessment of security-control effectiveness — and report security status to defined roles on a defined cadence. Deploy monitoring across hosts, networks, and applications, at the perimeter and interior, to detect attacks, indicators of compromise, unauthorized connections, and anomalous behaviour indicative of malicious acts, natural disasters, or errors. Analyze flagged anomalies promptly to determine whether they represent security events requiring further evaluation.
- domain
- Logging, Monitoring & Detection
- control_type
- detective
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- CA-7
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SI-4
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.16
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC7.2
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- DE.CM-01
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Continuous Controls Monitoring (ISCM) Cycle oversees UC-LOG-04 — Continuously monitor systems for anomalous activity
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates No security monitoring or supervision of privileged activity
- strength
- primary
- rationale
- Operating continuous monitoring across hosts, networks, and applications directly fills the absence-of-monitoring gap.
- Cybersecurity Assurance Review tests UC-LOG-04 — Continuously monitor systems for anomalous activity
- UC-LOG-04 — Continuously monitor systems for anomalous activity maps_to SI-4 — System Monitoring
- framework
- nist-800-53
- control_id
- SI-4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-04 — Continuously monitor systems for anomalous activity maps_to DE.CM-01 — Continuous Monitoring: Networks and network services are monitored to find potentially adverse events
- framework
- nist-csf-2
- control_id
- DE.CM-01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates Adversary reconnaissance and information gathering
- strength
- related
- rationale
- Perimeter monitoring detects active scanning/probing, catching the reconnaissance subset that generates observable network activity.
- UC-LOG-04 — Continuously monitor systems for anomalous activity maps_to CC7.2 — The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events.
- framework
- soc2
- control_id
- CC7.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Monitoring & Detection Operations operates UC-LOG-04 — Continuously monitor systems for anomalous activity
- SOC 2 Trust Services Readiness tests UC-LOG-04 — Continuously monitor systems for anomalous activity
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-LOG-04 — Continuously monitor systems for anomalous activity
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates Data exfiltration and theft of information by attackers
- strength
- primary
- rationale
- Monitoring for unauthorized connections and anomalous behavior (SI-4) detects exfiltration such as anomalous outbound transfers.
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates Attacks by capable, motivated threat actors
- strength
- primary
- rationale
- Continuous host/network/app monitoring to detect attacks and indicators of compromise is a first-order detective defense against active threat actors.
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates Coordinated multi-stage / APT campaigns
- strength
- primary
- rationale
- Perimeter-and-interior monitoring for IOCs and anomalous behavior detects lateral movement and persistence of multi-stage campaigns.
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates User error and mishandling of sensitive information
- strength
- related
- rationale
- Monitoring explicitly flags anomalous behavior indicative of errors, enabling detection and correction before harm spreads.
- UC-LOG-04 — Continuously monitor systems for anomalous activity maps_to A.8.16 — Monitoring activities
- framework
- iso-27001
- control_id
- A.8.16
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-04 — Continuously monitor systems for anomalous activity maps_to CA-7 — Continuous Monitoring
- framework
- nist-800-53
- control_id
- CA-7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.