unified
UC-LOG-05 — Correlate and analyze events centrally with threat intel
Aggregate logs and alerts into a central analysis capability (such as a SIEM) that correlates information from multiple internal and external sources and enriches it with cyber threat intelligence and contextual information. Review and analyze collected records on a defined cadence for indications of inappropriate or unusual activity, using record-reduction and on-demand report generation that does not alter the original records. Route findings and adverse-event information to authorized staff and tools, and communicate monitoring responsibilities and results internally so accountable parties can act.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Logging, Monitoring & Detection
- type
- detective
- category
- technical
Details
- unified_id
- UC-LOG-05
- title
- Correlate and analyze events centrally with threat intel
- statement
- Aggregate logs and alerts into a central analysis capability (such as a SIEM) that correlates information from multiple internal and external sources and enriches it with cyber threat intelligence and contextual information. Review and analyze collected records on a defined cadence for indications of inappropriate or unusual activity, using record-reduction and on-demand report generation that does not alter the original records. Route findings and adverse-event information to authorized staff and tools, and communicate monitoring responsibilities and results internally so accountable parties can act.
- domain
- Logging, Monitoring & Detection
- control_type
- detective
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- AU-6
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AU-7
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- DE.AE-02
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- DE.AE-03
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- DE.AE-06
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- DE.AE-07
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-LOG-05 — Correlate and analyze events centrally with threat intel mitigates No security monitoring or supervision of privileged activity
- strength
- primary
- rationale
- A central analysis capability that reviews records on cadence and routes findings to authorized staff supplies the missing monitoring and escalation.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel maps_to AU-6 — Audit Record Review, Analysis, and Reporting
- framework
- nist-800-53
- control_id
- AU-6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel mitigates Adversary reconnaissance and information gathering
- strength
- related
- rationale
- Threat-intel-enriched correlation flags distributed scanning and traffic to known reconnaissance infrastructure.
- Security Monitoring & Detection Operations operates UC-LOG-05 — Correlate and analyze events centrally with threat intel
- Cybersecurity Assurance Review tests UC-LOG-05 — Correlate and analyze events centrally with threat intel
- UC-LOG-05 — Correlate and analyze events centrally with threat intel maps_to DE.AE-07 — Adverse Event Analysis: Cyber threat intelligence and other contextual information are integrated into the analysis
- framework
- nist-csf-2
- control_id
- DE.AE-07
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel mitigates Coordinated multi-stage / APT campaigns
- strength
- primary
- rationale
- Central correlation across multiple sources enriched with threat intel connects dispersed signals to detect multi-stage APT campaigns.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel maps_to DE.AE-06 — Adverse Event Analysis: Information on adverse events is provided to authorized staff and tools
- framework
- nist-csf-2
- control_id
- DE.AE-06
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel maps_to DE.AE-03 — Adverse Event Analysis: Information is correlated from multiple sources
- framework
- nist-csf-2
- control_id
- DE.AE-03
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel mitigates Data exfiltration and theft of information by attackers
- strength
- primary
- rationale
- Correlating events (e.g., beaconing plus large transfers) against threat-intel indicators detects exfiltration patterns.
- Security Control Assessment & POA&M Remediation tests UC-LOG-05 — Correlate and analyze events centrally with threat intel
- UC-LOG-05 — Correlate and analyze events centrally with threat intel maps_to DE.AE-02 — Adverse Event Analysis: Potentially adverse events are analyzed to better understand associated activities
- framework
- nist-csf-2
- control_id
- DE.AE-02
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel mitigates Attacks by capable, motivated threat actors
- strength
- primary
- rationale
- SIEM correlation and threat-intel enrichment detect attacks by matching observed activity to known adversary indicators.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel maps_to AU-7 — Audit Record Reduction and Report Generation
- framework
- nist-800-53
- control_id
- AU-7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.