workflow
Security Monitoring & Detection Operations
Each weekly cycle is a recurring instance attached to the existing continuous security-monitoring Control item (domains: logging_monitoring_detection, control_type: detective, frequency: weekly) — the cycle enriches that standing Control with its operating record, never creating a duplicate control. It consumes the prior cycle's carry-forward (unresolved queue Issues, open watchlist entries, open corrective actions) and the documented continuous-monitoring strategy (a Policy item linked to the Control), and produces named deliverables: the deployment coverage-and-effectiveness assessment, the enriched central SIEM analysis queue, the maintained detection watchlist, and the signed cycle security-status report. In scope: verifying monitoring deployment and effectiveness, working the central SIEM threat-intel analysis queue, triaging flagged anomalies, maintaining the detection watchlist, reporting security status to the defined roles, and verifying continuous protection-service health and tuning across hosts, networks, and applications at both the perimeter and the interior. Out of scope: incident containment, eradication, and recovery — confirmed security events are handed off mid-cycle to the Security Incident Response workflow rather than duplicated here.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- domains
- controls
- standards
- nist-csf-2
- nist-800-53
- iso-27001
- soc2
- sourceTemplateId
- workflow-library:controls-security-monitoring-detection-operations
- releaseId
- sha256:2264ccb2a62c35b5cd25519eb830d768654f8034602856c3d593927ef0ebf28c
- canonicalUrl
- https://workflow-library.com/all/?w=controls-security-monitoring-detection-operations
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-LOG-04
- UC-LOG-05
- UC-BCDR-13
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:2264ccb2a62c35b5cd25519eb830d768654f8034602856c3d593927ef0ebf28c
Connections
- Security Monitoring & Detection Operations operates UC-LOG-05 — Correlate and analyze events centrally with threat intel
- Security Monitoring & Detection Operations operates UC-LOG-04 — Continuously monitor systems for anomalous activity
- Security Monitoring & Detection Operations operates UC-BCDR-13 — Operate continuous security protection services