Networks, systems and applications are to be monitored for anomalous behaviour, with appropriate steps taken to evaluate possible information security incidents. Purpose: spot abnormal behaviour and possible incidents. Guidance: decide the scope and depth of monitoring from business and security requirements and applicable law, and keep monitoring records for defined periods. Consider monitoring inbound and outbound network, system and application traffic; access to systems, servers, network equipment, the monitoring system itself and critical applications; critical or administrator-level configuration files; logs from security tools such as anti-virus, IDS, IPS, web filters, firewalls and DLP; system and network event logs; checks that running code is authorized and untampered, for example not recompiled with unwanted additions; and resource use and performance (CPU, disks, memory, bandwidth). Establish a baseline of normal behaviour, reviewing use at normal and peak times and each user's or group's usual access times, locations and frequency, and monitor for deviations such as unplanned termination of processes or applications; malware-like activity or traffic from known malicious addresses or domains, such as botnet controllers; known attack signatures like denial of service or buffer overflows; unusual system behaviour such as keystroke logging, process injection or non-standard protocol use; bottlenecks and overloads (queuing, latency, jitter); actual or attempted unauthorized access; unauthorized scanning of applications, systems and networks; successful and failed attempts on protected resources such as name servers, portals and file systems; and user or system behaviour that departs from expectations. Use continuous monitoring tools, in real time or at intervals as needs and capabilities allow, able to handle large data volumes, adapt to changing threats, notify in real time and recognize signatures and behaviour patterns. Configure automated alerts on predefined thresholds through consoles, email or messaging, tuned to the baseline to limit false positives; have dedicated, trained staff to interpret and respond to alerts, with redundant systems and processes for receiving them. Share abnormal events with relevant parties so that audit, security evaluation, vulnerability scanning and monitoring improve (5.25); respond to positive indicators promptly to limit harm (5.26); and identify and address false positives, tuning tools to reduce them. Other information: monitoring can be strengthened with threat intelligence (5.7), machine learning and AI, block and allow lists, technical assessments such as vulnerability assessments, penetration tests, attack simulations and response exercises that help set baselines, performance monitoring, and logs combined with monitoring; intrusion detection systems can be baselined to expected activity; watching for anomalous communications helps find botnet infections controlled from outside.
This control maps to 202 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 8.16 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 202 it maps to, and the evidence behind each claim, over MCP and REST.