C5 (Germany)
C5: Operations

C5 (Germany) C5-OPS-13: Logging and Monitoring - Identification of Events

Analyse logging data automatically against the defined event criteria, including correlation of relationships between events, and report identified events automatically to the appropriate departments for prompt evaluation and action.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 75 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 7 controls

  • 10.2.1 10.2.1 Audit logging enabled on all system components
  • 10.2.1.2 10.2.1.2 Logs capture all administrative actions
  • 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts
  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 10.4.1.1 10.4.1.1 Automated mechanisms used for audit log review
  • 5.3.4 5.3.4 Anti-malware audit logs enabled and retained

CIS Controls v8 · 5 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-17.9 Establish and Maintain Security Incident Thresholds
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.2 Collect Audit Logs
  • CIS-8.5 Collect Detailed Audit Logs

FedRAMP High · 5 controls

  • AU-2 Event Logging
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(3) Correlate Audit Record Repositories
  • SI-4 System Monitoring
  • SI-4(5) System-Generated Alerts

FedRAMP Moderate · 5 controls

  • AU-2 Event Logging
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(3) Correlate Audit Record Repositories
  • SI-4 System Monitoring
  • SI-4(5) System-Generated Alerts

CMMC 2.0 · 4 controls

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

ACSC Essential Eight · 3 controls

  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • E8-ADMIN-ML3 Restrict Administrative Privileges (ML3)
  • E8-APP-ML2 Application Control (ML2)
  • ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts
  • ASBv3-LT-1 Enable threat detection capabilities
  • DP-2 Monitor anomalies and threats targeting sensitive data

HIPAA Security Rule · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-31 Hunt to discover incidents (Very Good)

ISO 27001:2022 · 2 controls

  • 5.25 Assessment and decision on information security events
  • 8.16 Monitoring activities

ISO 27002:2022 · 2 controls

  • 5.25 Assessment and decision on information security events
  • 8.16 Monitoring activities

ISO 27017:2015 · 2 controls

  • 12.4 Logging and monitoring
  • CLD.12.4.5 Monitoring of cloud services

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.11.2e Threat Hunting
  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components
  • CBPR-PR-32 Detection, prevention and response measures

APRA CPS 234 · 1 control

  • CPS234-30 Detection and Response Mechanisms

DORA · 1 control

ISO 27018:2019 · 1 control

  • 12.4 Logging and monitoring

ISO 27701:2019 · 1 control

  • 6.9.4 Logging and monitoring

NIS2 Directive · 1 control

SOC 2 · 1 control

  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in C5: Operations

You are reading one control. How much of C5 (Germany) have you already done?

C5 (Germany) C5-OPS-13 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of C5 (Germany) your existing evidence covers. Hold Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 and 95 of 121 C5 (Germany) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 pair alone.

Query this from an agent

The graph holds this control, the 75 it maps to, and the evidence behind each claim, over MCP and REST.