unified
UC-LOG-09 — Monitor providers and exchange audit data across organizations
Define monitoring requirements for external service providers and monitor their activities, service status, and security-relevant events against contractual obligations, reviewing provider-supplied logs and reports on a defined cadence. Where audit trails cross organizational boundaries, agree methods for coordinating, exchanging, and protecting audit information with the external parties and preserve the identity context needed to trace cross-organizational actions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Logging, Monitoring & Detection
- type
- detective
- category
- administrative
Details
- unified_id
- UC-LOG-09
- title
- Monitor providers and exchange audit data across organizations
- statement
- Define monitoring requirements for external service providers and monitor their activities, service status, and security-relevant events against contractual obligations, reviewing provider-supplied logs and reports on a defined cadence. Where audit trails cross organizational boundaries, agree methods for coordinating, exchanging, and protecting audit information with the external parties and preserve the identity context needed to trace cross-organizational actions.
- domain
- Logging, Monitoring & Detection
- control_type
- detective
- control_category
- administrative
- members
- framework
- nist-csf-2
- control_id
- DE.CM-06
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AU-16
- coverage
- full
- relationship
- superset_of
- framework
- aiuc-1
- control_id
- E009
- coverage
- partial
- delta
- monitoring of third-party API connections, integrations, and sessions into AI systems, including revocation of stale access
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-LOG-09 — Monitor providers and exchange audit data across organizations mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Reviewing provider logs and monitoring their activity detects data theft routed through third-party channels.
- UC-LOG-09 — Monitor providers and exchange audit data across organizations mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- Monitoring provider security-relevant events detects the malicious or compromised supplier threat vector.
- Third-Party ICT Vendor Regulatory Assurance oversees UC-LOG-09 — Monitor providers and exchange audit data across organizations
- UC-LOG-09 — Monitor providers and exchange audit data across organizations maps_to DE.CM-06 — Continuous Monitoring: External service provider activities and services are monitored to find potentially adverse events
- framework
- nist-csf-2
- control_id
- DE.CM-06
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Third-Party Vendor Risk Lifecycle oversees UC-LOG-09 — Monitor providers and exchange audit data across organizations
- Network & Provider Service Monitoring operates UC-LOG-09 — Monitor providers and exchange audit data across organizations
- UC-LOG-09 — Monitor providers and exchange audit data across organizations mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Monitoring provider activity against contractual obligations detects the supply-chain vector campaigns exploit to enter.
- UC-LOG-09 — Monitor providers and exchange audit data across organizations maps_to AU-16 — Cross-organizational Audit Logging
- framework
- nist-800-53
- control_id
- AU-16
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-09 — Monitor providers and exchange audit data across organizations maps_to E009 — Monitor third-party access
- framework
- aiuc-1
- control_id
- E009
- coverage
- partial
- delta
- monitoring of third-party API connections, integrations, and sessions into AI systems, including revocation of stale access
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-09 — Monitor providers and exchange audit data across organizations mitigates Missing or insufficient logging and audit trails
- strength
- primary
- rationale
- Exchanging audit data across boundaries and preserving identity context to trace cross-organizational actions remedies audit-trail gaps at provider handoffs.