{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Logging, Monitoring & Detection","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-04","description":"Operate continuous monitoring under a documented strategy that defines what is monitored, the metrics, and the frequencies — including ongoing assessment of security-control effectiveness — and report security status to defined roles on a defined cadence. Deploy monitoring across hosts, networks, and applications, at the perimeter and interior, to detect attacks, indicators of compromise, unauthorized connections, and anomalous behaviour indicative of malicious acts, natural disasters, or errors. Analyze flagged anomalies promptly to determine whether they represent security events requiring further evaluation.","details":{"control_category":"technical","control_type":"detective","domain":"Logging, Monitoring & Detection","guidance":[],"members":[{"control_id":"CA-7","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SI-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.8.16","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"CC7.2","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"DE.CM-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"}],"statement":"Operate continuous monitoring under a documented strategy that defines what is monitored, the metrics, and the frequencies — including ongoing assessment of security-control effectiveness — and report security status to defined roles on a defined cadence. Deploy monitoring across hosts, networks, and applications, at the perimeter and interior, to detect attacks, indicators of compromise, unauthorized connections, and anomalous behaviour indicative of malicious acts, natural disasters, or errors. Analyze flagged anomalies promptly to determine whether they represent security events requiring further evaluation.","title":"Continuously monitor systems for anomalous activity","unified_id":"UC-LOG-04"},"id":"uc:UC-LOG-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-04","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"UC-LOG-04 — Continuously monitor systems for anomalous activity","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0710c2c06139849a73f76fede4ef76ad75bdc3f599b5ba12e2638006dbbe821b","properties":{},"sourceDetailPath":"/data/v1/records/wf-c1-f9e3db77.json","sourceId":"wf:C1","targetDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","targetId":"uc:UC-LOG-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0b3ae93e3aeb93d4b69dd16e98ced1954a4e17e69f583e3ebd33ba5571e823aa","properties":{"rationale":"Operating continuous monitoring across hosts, networks, and applications directly fills the absence-of-monitoring gap.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/risk-log-no-monitoring-supervision-712fe573.json","targetId":"risk:log-no-monitoring-supervision","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:170c42229ec9a57072ebf720b3ffb3736229acdb6c363100a6b6a15abe9a5e73","properties":{},"sourceDetailPath":"/data/v1/records/wf-a1-f09c8201.json","sourceId":"wf:A1","targetDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","targetId":"uc:UC-LOG-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:296e9390194eab0164131a3521fe32f15aab47e62269daccb772e914d46f04fc","properties":{"control_id":"SI-4","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-4-6048a58e.json","targetId":"ctrl:nist-800-53:SI-4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:60656af39e5efdd590728857fde49ca2a95f3892cc4a55b7f9d8b342e62460fc","properties":{"control_id":"DE.CM-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-01-5a17881e.json","targetId":"ctrl:nist-csf-2:DE.CM-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8b3dc8d32fb0a5fb775f0657e998c546292281ac3c06e98f1dc82074be05acbb","properties":{"rationale":"Perimeter monitoring detects active scanning/probing, catching the reconnaissance subset that generates observable network activity.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/risk-cyber-reconnaissance-3a7a6c33.json","targetId":"risk:cyber-reconnaissance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:93c7b4ecafc7357939d7211611c3815656b5f01ce4be2df9e7bbd7d1239fc127","properties":{"control_id":"CC7.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/ctrl-soc2-cc7-2-7ca85bf1.json","targetId":"ctrl:soc2:CC7.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:983a9be40f6813a4d7d516887840738a76058c5de2b25f4daae96ef7fef2886d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c53-cbf08eb0.json","sourceId":"wf:C53","targetDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","targetId":"uc:UC-LOG-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9e610e6cde43ab1ce08568903de5db9e8fd17bfd1567d3e62590d90437f448ad","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","targetId":"uc:UC-LOG-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9fa77627d50cfbb6b1d6c525a00a95f3a26ceb93899aa98a9870f43ab3b5bdb5","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","targetId":"uc:UC-LOG-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b9dadfb07326923527488fb657fa7640ae4bb4471959de932d334a486591a2f4","properties":{"rationale":"Monitoring for unauthorized connections and anomalous behavior (SI-4) detects exfiltration such as anomalous outbound transfers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bbe0ad5da2b39a58b8954b219d172888ed0425e4df42439924f053d8affb1377","properties":{"rationale":"Continuous host/network/app monitoring to detect attacks and indicators of compromise is a first-order detective defense against active threat actors.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d11ffe0ac5bfc702e0a30dddda5b08268f3392e543773abf1e7e108ee8742c83","properties":{"rationale":"Perimeter-and-interior monitoring for IOCs and anomalous behavior detects lateral movement and persistence of multi-stage campaigns.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/risk-cyber-coordinated-campaign-b5879769.json","targetId":"risk:cyber-coordinated-campaign","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f3641ecbfb7a80e3af4657972f91c5a42ee0cca975f40e172ae62182e13871c9","properties":{"rationale":"Monitoring explicitly flags anomalous behavior indicative of errors, enabling detection and correction before harm spreads.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/risk-aware-user-error-mishandling-149a1d3b.json","targetId":"risk:aware-user-error-mishandling","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fb186e243e2e1fe03b9317a3e8c9db240c9f551928cd60e4775e7899ae8cd547","properties":{"control_id":"A.8.16","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-16-ca49cbfe.json","targetId":"ctrl:iso-27001:A.8.16","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fddb5d92074b08d62c7a1752633b166cbf10867d3f2a39bbdecc70ceabf02c64","properties":{"control_id":"CA-7","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ca-7-a6cb4db3.json","targetId":"ctrl:nist-800-53:CA-7","type":"maps_to"}],"schemaVersion":1}
