Security monitoring practices are implemented at the network or infrastructure, application and transaction layers so the DSP can scan its environment for threats and act on anomalies; monitoring is a joint responsibility of the ATO and the DSP. The DSP demonstrates monitoring processes, regular threat scanning and the actions taken when anomalies are detected. Evidence: an alerting intrusion detection system, an intrusion prevention system protecting endpoints, an anomaly detection approach or security event dashboard (which may include business or system rules against fraud), and a policy on actions when anomalies are found. For category D it applies where the product can relay data to the DSP; for category E it is an optional consideration.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.