Requires procedures to be established and used for identifying evidence relating to information security events, then collecting, acquiring and preserving it.
What else in your programme already covers this
This control maps to 79 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-AU-10 Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined]
NIST800-AU-16 Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries
NIST800-AU-6 Audit record review, analysis, and reporting
NIST800-IR-9 Information Spillage Response. Respond to information spills by: Assigning [organization-defined] with responsibility for responding to information spills; Identifying the specific information involved in the system contamination; Alerting [organization-defined] of the information spill using a
SOC2-CC2.1 COSO principle 13: Obtains and generates relevant, quality information
SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
SOC2-CC7.1 Detection and monitoring procedures for security events are in place
SOC2-CC7.3 Evaluates security events to determine incident status
SOC2-CC7.4 Responds to identified security incidents through defined procedures
SOC2-P6.2 Records of personal information disclosures are maintained
SOC2-P6.3 Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy. The following point of focus, which
IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [Assignment: organization-defined controls]
IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [Assignment: organization-defined controls]
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.28 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.