{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Logging, Monitoring & Detection","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-18","description":"Systems generate log records that are protected and made available for continuous monitoring. Performance, capacity, and security events are monitored against thresholds, with alerts triaged and incidents identified and resolved through a tracked process. Resource use is projected and tuned to meet current and future capacity requirements.","details":{"control_category":"technical","control_type":"detective","domain":"Logging, Monitoring & Detection","guidance":[],"members":[{"control_id":"PR.PS-04","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.8.6","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"SOC1-11","coverage":"full","framework":"soc1","relationship":"superset_of"}],"statement":"Systems generate log records that are protected and made available for continuous monitoring. Performance, capacity, and security events are monitored against thresholds, with alerts triaged and incidents identified and resolved through a tracked process. Resource use is projected and tuned to meet current and future capacity requirements.","title":"Log and monitor system activity, capacity, and incidents","unified_id":"UC-ACCESS-18"},"id":"uc:UC-ACCESS-18","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-18","sourceIds":["iso-27001","nist-csf-2","soc1"],"sourceUrl":null,"title":"UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0bece6d03d1c8691792aecc2392eab2ee047ecc943ddfa6614954a6cc7b2c04b","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","targetId":"uc:UC-ACCESS-18","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35e1dfb346a72fd0c22d2413ff5a7d57a2ebd258234bdaa359d941754b0c242b","properties":{"rationale":"Systems generate protected log records made available for continuous monitoring, directly remedying absent/insufficient audit trails.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-log-missing-audit-trail-37d1ba80.json","targetId":"risk:log-missing-audit-trail","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4987cfed4954248b8ed56bc0bbc3dca0d46b95d8bbd753c0fa0c8c6fab25422e","properties":{"rationale":"Incident identification and capacity/performance monitoring surface error- and misconfiguration-driven incidents, enabling correction that limits impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-aware-user-error-mishandling-149a1d3b.json","targetId":"risk:aware-user-error-mishandling","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5a3941e3dbce77474b4dd92999dc19080f3b900b1e9483c06f11455d8ecf5867","properties":{},"sourceDetailPath":"/data/v1/records/wf-s15-604d223f.json","sourceId":"wf:S15","targetDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","targetId":"uc:UC-ACCESS-18","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ea9a605ea5162b98dfaf780e8acd3f3d613562504140ed2fa84d3b38f3d46c0","properties":{"control_id":"A.8.6","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-6-d9abb4dc.json","targetId":"ctrl:iso-27001:A.8.6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6b18a958918d0985d782da97353efae275c15ef9f3eb3f2fdb659a60f7856944","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","targetId":"uc:UC-ACCESS-18","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6c815b812ba264ef62d6cf7e0c231c815cef0e6891cd1d8eb074d6564b155aa3","properties":{"rationale":"Continuously monitors security events against thresholds with alert triage and tracked incident resolution, filling the no-monitoring gap.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-log-no-monitoring-supervision-712fe573.json","targetId":"risk:log-no-monitoring-supervision","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7c3a185818b8aa491bee8c358ee5433277ecf04932f4c54f7a61ebd250cc7cf1","properties":{"rationale":"Monitors performance/capacity against thresholds and projects/tunes resource use, directly reducing capacity-driven outages; incident tracking shortens recovery.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-bcdr-it-resilience-outage-18dfc108.json","targetId":"risk:bcdr-it-resilience-outage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8042e50c8400feb9ba8232e6e9b8b7dba985fb195e97a397d35b5d09e90e8b9b","properties":{"control_id":"SOC1-11","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-11-9b7842c1.json","targetId":"ctrl:soc1:SOC1-11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d9c1f43d9ea36c1e11f537e90124df813ec8c275a3a177944bf1968968ccf663","properties":{"control_id":"PR.PS-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ps-04-d4dac561.json","targetId":"ctrl:nist-csf-2:PR.PS-04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f58e9acd1374bdbce84d3819c1f1ddf398cf90c365abed4378c3b5e88b182afd","properties":{"rationale":"Security-event monitoring with alert triage contributes to detecting attacks, though specialized detection sits in dedicated SIEM/IDS controls.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"}],"schemaVersion":1}
