unified
UC-LOG-07 — Monitor user sessions and personnel activity
Monitor user and administrator activity for signs of misuse: capture and review session activity for defined high-risk circumstances such as privileged or remote sessions, with legal review and any required disclosure to users, and monitor personnel technology usage against acceptable-use expectations to surface potentially adverse events. Restrict access to captured session data to authorized reviewers and involve HR and legal counsel in handling findings.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Logging, Monitoring & Detection
- type
- detective
- category
- technical
Details
- unified_id
- UC-LOG-07
- title
- Monitor user sessions and personnel activity
- statement
- Monitor user and administrator activity for signs of misuse: capture and review session activity for defined high-risk circumstances such as privileged or remote sessions, with legal review and any required disclosure to users, and monitor personnel technology usage against acceptable-use expectations to surface potentially adverse events. Restrict access to captured session data to authorized reviewers and involve HR and legal counsel in handling findings.
- domain
- Logging, Monitoring & Detection
- control_type
- detective
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- AU-14
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- DE.CM-03
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-LOG-07 — Monitor user sessions and personnel activity maps_to AU-14 — Session Audit
- framework
- nist-800-53
- control_id
- AU-14
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-LOG-07 — Monitor user sessions and personnel activity
- User Activity & External Exposure Monitoring operates UC-LOG-07 — Monitor user sessions and personnel activity
- UC-LOG-07 — Monitor user sessions and personnel activity mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Capturing and reviewing privileged/admin session activity detects authorized users exploiting access beyond permitted scope.
- UC-LOG-07 — Monitor user sessions and personnel activity mitigates Manual journal entries and management-override risk
- strength
- related
- rationale
- Monitoring privileged/admin sessions detects management override executed via back-channel privileged access that bypasses application-level journal-entry controls.
- UC-LOG-07 — Monitor user sessions and personnel activity maps_to DE.CM-03 — Continuous Monitoring: Personnel activity and technology usage are monitored to find potentially adverse events
- framework
- nist-csf-2
- control_id
- DE.CM-03
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-07 — Monitor user sessions and personnel activity mitigates No security monitoring or supervision of privileged activity
- strength
- primary
- rationale
- Monitoring administrator and privileged/remote sessions for misuse directly supplies the supervision of privileged activity the risk describes as absent.
- UC-LOG-07 — Monitor user sessions and personnel activity mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Session and personnel-usage monitoring detects insiders locating or moving sensitive data for theft.
- UC-LOG-07 — Monitor user sessions and personnel activity mitigates User error and mishandling of sensitive information
- strength
- related
- rationale
- Monitoring personnel technology usage against acceptable-use expectations surfaces non-malicious mishandling of sensitive information.