The I&T infrastructure and the events arising in it are monitored, and operations logs keep enough time-ordered information that the sequence of operations, and the activity around them, can be rebuilt and reviewed: the level of detail logged is chosen according to risk and performance; a list of the infrastructure assets to watch is kept, based on how critical each service is and how configuration items relate to the services that depend on them; rules detect and log breached thresholds and event conditions, tuned so that logs are not flooded with trivial events; event logs are generated and kept long enough to support investigations; incident tickets are raised without delay when monitoring finds a deviation from a threshold; and procedures for watching event logs include regular review.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.