{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Logging, Monitoring & Detection","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-05","description":"Aggregate logs and alerts into a central analysis capability (such as a SIEM) that correlates information from multiple internal and external sources and enriches it with cyber threat intelligence and contextual information. Review and analyze collected records on a defined cadence for indications of inappropriate or unusual activity, using record-reduction and on-demand report generation that does not alter the original records. Route findings and adverse-event information to authorized staff and tools, and communicate monitoring responsibilities and results internally so accountable parties can act.","details":{"control_category":"technical","control_type":"detective","domain":"Logging, Monitoring & Detection","guidance":[],"members":[{"control_id":"AU-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AU-7","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"DE.AE-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"DE.AE-03","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"DE.AE-06","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"DE.AE-07","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"}],"statement":"Aggregate logs and alerts into a central analysis capability (such as a SIEM) that correlates information from multiple internal and external sources and enriches it with cyber threat intelligence and contextual information. Review and analyze collected records on a defined cadence for indications of inappropriate or unusual activity, using record-reduction and on-demand report generation that does not alter the original records. Route findings and adverse-event information to authorized staff and tools, and communicate monitoring responsibilities and results internally so accountable parties can act.","title":"Correlate and analyze events centrally with threat intel","unified_id":"UC-LOG-05"},"id":"uc:UC-LOG-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-05","sourceIds":["nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-LOG-05 — Correlate and analyze events centrally with threat intel","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0e777729a230b4f92989de3a607fb6970f1e9ed98cdfffab04aab914e0175290","properties":{"rationale":"A central analysis capability that reviews records on cadence and routes findings to authorized staff supplies the missing monitoring and escalation.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/risk-log-no-monitoring-supervision-712fe573.json","targetId":"risk:log-no-monitoring-supervision","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:193f668891e750f9d5ce591c95ad93994ee47dce9942ae128f4655fad87fa36a","properties":{"control_id":"AU-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-au-6-0ec5f80c.json","targetId":"ctrl:nist-800-53:AU-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3183b71e7b89264ebce5205e8eaf7d00921d999ca3396bc723e43d276ef19733","properties":{"rationale":"Threat-intel-enriched correlation flags distributed scanning and traffic to known reconnaissance infrastructure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/risk-cyber-reconnaissance-3a7a6c33.json","targetId":"risk:cyber-reconnaissance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:39f18e04d3d5f4f20aebb3067d2197f33a603fe34b15f0c52a85e73ad998d214","properties":{},"sourceDetailPath":"/data/v1/records/wf-c53-cbf08eb0.json","sourceId":"wf:C53","targetDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","targetId":"uc:UC-LOG-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:49080fcf25ba6d133104c2a0b3241a81044f4eb4d087a991df62bf93e4b8b04e","properties":{},"sourceDetailPath":"/data/v1/records/wf-a1-f09c8201.json","sourceId":"wf:A1","targetDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","targetId":"uc:UC-LOG-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:77ab17bd71037f78d1ce06542e69073a9f776b5bcfa21aaf1c7a7cc9cdd890f6","properties":{"control_id":"DE.AE-07","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-07-a597b302.json","targetId":"ctrl:nist-csf-2:DE.AE-07","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:addce231f3d916e566dba07dd45ef3b05099e207cc115ee9a5654265ff810e91","properties":{"rationale":"Central correlation across multiple sources enriched with threat intel connects dispersed signals to detect multi-stage APT campaigns.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/risk-cyber-coordinated-campaign-b5879769.json","targetId":"risk:cyber-coordinated-campaign","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b577e76b97bde031b8cbb6456709baae08a4387b8f2648b91938cd3aade295f2","properties":{"control_id":"DE.AE-06","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-06-88d06373.json","targetId":"ctrl:nist-csf-2:DE.AE-06","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b758bd0b1f0477a409c095ce01264b38a4838e7e579169c449187a5183a01767","properties":{"control_id":"DE.AE-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-03-f45e152f.json","targetId":"ctrl:nist-csf-2:DE.AE-03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d253870d8a042796fc22983c940c69373fead8d84e7a7844fc3c88e556b1106a","properties":{"rationale":"Correlating events (e.g., beaconing plus large transfers) against threat-intel indicators detects exfiltration patterns.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d4cfaad153d399ec0ffddaf02255d416089cce6f20f0fe360de0a23e47260f06","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","targetId":"uc:UC-LOG-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d64f32a946a805b1fa036159aa56cb168af7d7bc1b98bd605001f926402246e8","properties":{"control_id":"DE.AE-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-02-1f4071e1.json","targetId":"ctrl:nist-csf-2:DE.AE-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f98770c87f438334b14b65b4fe3ee1b7ef1495a80f1115a811ae654d21e427c5","properties":{"rationale":"SIEM correlation and threat-intel enrichment detect attacks by matching observed activity to known adversary indicators.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ffc937bfae72d82ce59151500f5affda4864de7e7cdc755a68e4e553d9ac974c","properties":{"control_id":"AU-7","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-au-7-e938da46.json","targetId":"ctrl:nist-800-53:AU-7","type":"maps_to"}],"schemaVersion":1}
