ATO Digital Service Provider (DSP) Operational Security Framework
Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

ATO Digital Service Provider (DSP) Operational Security Framework SEC.MONITOR: Security monitoring at network, application and transaction layers

Security monitoring practices are implemented at the network or infrastructure, application and transaction layers so the DSP can scan its environment for threats and act on anomalies; monitoring is a joint responsibility of the ATO and the DSP. The DSP demonstrates monitoring processes, regular threat scanning and the actions taken when anomalies are detected. Evidence: an alerting intrusion detection system, an intrusion prevention system protecting endpoints, an anomaly detection approach or security event dashboard (which may include business or system rules against fraud), and a policy on actions when anomalies are found. For category D it applies where the product can relay data to the DSP; for category E it is an optional consideration.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ISM-1034 HIPS or EDR on critical servers
  • ISM-1228 Analysing cyber security events for incidents

ISO 27002:2022 · 1 control

  • 8.16 Monitoring activities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.