unified

UC-LOG-05 — Correlate and analyze events centrally with threat intel

Aggregate logs and alerts into a central analysis capability (such as a SIEM) that correlates information from multiple internal and external sources and enriches it with cyber threat intelligence and contextual information. Review and analyze collected records on a defined cadence for indications of inappropriate or unusual activity, using record-reduction and on-demand report generation that does not alter the original records. Route findings and adverse-event information to authorized staff and tools, and communicate monitoring responsibilities and results internally so accountable parties can act.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Logging, Monitoring & Detection
type
detective
category
technical

Details

unified_id
UC-LOG-05
title
Correlate and analyze events centrally with threat intel
statement
Aggregate logs and alerts into a central analysis capability (such as a SIEM) that correlates information from multiple internal and external sources and enriches it with cyber threat intelligence and contextual information. Review and analyze collected records on a defined cadence for indications of inappropriate or unusual activity, using record-reduction and on-demand report generation that does not alter the original records. Route findings and adverse-event information to authorized staff and tools, and communicate monitoring responsibilities and results internally so accountable parties can act.
domain
Logging, Monitoring & Detection
control_type
detective
control_category
technical
members
  • framework
    nist-800-53
    control_id
    AU-6
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    AU-7
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    DE.AE-02
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    DE.AE-03
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    DE.AE-06
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    DE.AE-07
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections