ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.16: Monitoring activities

Networks, systems and applications are to be monitored for anomalous behaviour, with appropriate steps taken to evaluate possible information security incidents. Purpose: spot abnormal behaviour and possible incidents. Guidance: decide the scope and depth of monitoring from business and security requirements and applicable law, and keep monitoring records for defined periods. Consider monitoring inbound and outbound network, system and application traffic; access to systems, servers, network equipment, the monitoring system itself and critical applications; critical or administrator-level configuration files; logs from security tools such as anti-virus, IDS, IPS, web filters, firewalls and DLP; system and network event logs; checks that running code is authorized and untampered, for example not recompiled with unwanted additions; and resource use and performance (CPU, disks, memory, bandwidth). Establish a baseline of normal behaviour, reviewing use at normal and peak times and each user's or group's usual access times, locations and frequency, and monitor for deviations such as unplanned termination of processes or applications; malware-like activity or traffic from known malicious addresses or domains, such as botnet controllers; known attack signatures like denial of service or buffer overflows; unusual system behaviour such as keystroke logging, process injection or non-standard protocol use; bottlenecks and overloads (queuing, latency, jitter); actual or attempted unauthorized access; unauthorized scanning of applications, systems and networks; successful and failed attempts on protected resources such as name servers, portals and file systems; and user or system behaviour that departs from expectations. Use continuous monitoring tools, in real time or at intervals as needs and capabilities allow, able to handle large data volumes, adapt to changing threats, notify in real time and recognize signatures and behaviour patterns. Configure automated alerts on predefined thresholds through consoles, email or messaging, tuned to the baseline to limit false positives; have dedicated, trained staff to interpret and respond to alerts, with redundant systems and processes for receiving them. Share abnormal events with relevant parties so that audit, security evaluation, vulnerability scanning and monitoring improve (5.25); respond to positive indicators promptly to limit harm (5.26); and identify and address false positives, tuning tools to reduce them. Other information: monitoring can be strengthened with threat intelligence (5.7), machine learning and AI, block and allow lists, technical assessments such as vulnerability assessments, penetration tests, attack simulations and response exercises that help set baselines, performance monitoring, and logs combined with monitoring; intrusion detection systems can be baselined to expected activity; watching for anomalous communications helps find botnet infections controlled from outside.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 202 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 28 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-2(7) Privileged User Accounts
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • AU-7(1) Automatic Processing
  • CA-7 Continuous Monitoring
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • IR-1 Policy and Procedures
  • IR-4(1) Automated Incident Handling Processes
  • IR-5 Incident Monitoring
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • MA-4 Nonlocal Maintenance
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SC-7 Boundary Protection
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1))
  • SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16))
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(23) System Monitoring | Host-based Devices (SI-4(23))
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives
  • SI-6 Security and Privacy Function Verification (SI-6)
  • SI-7(7) Integration of Detection and Response
  • SR-10 Inspection of Systems or Components (SR-10)

FedRAMP Moderate · 28 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-2(7) Privileged User Accounts
  • AU-6 Audit Record Review, Analysis, and Reporting
  • AU-6(1) Automated Process Integration
  • AU-6(3) Correlate Audit Record Repositories
  • AU-7(1) Automatic Processing
  • CA-7 Continuous Monitoring
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • IR-1 Policy and Procedures
  • IR-4(1) Automated Incident Handling Processes
  • IR-5 Incident Monitoring
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • MA-4 Nonlocal Maintenance
  • SA-1 Policy and Procedures
  • SA-2 Allocation of Resources
  • SC-7 Boundary Protection
  • SI-4 System Monitoring
  • SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1))
  • SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16))
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))
  • SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis
  • SI-4(23) System Monitoring | Host-based Devices (SI-4(23))
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-4(5) System-Generated Alerts
  • SI-5 Security Alerts, Advisories, and Directives
  • SI-6 Security and Privacy Function Verification (SI-6)
  • SI-7(7) Integration of Detection and Response
  • SR-10 Inspection of Systems or Components (SR-10)

NIST SP 800-53 Rev 5 · 14 controls

ACSC Essential Eight · 13 controls

  • E8-APP-ML3 Application Control (ML3)
  • E8-ADMIN-ISM-0109 Restrict administrative privileges (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events
  • E8-ADMIN-ISM-1906 Restrict administrative privileges (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events
  • E8-ADMIN-ISM-1907 Restrict administrative privileges (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events
  • E8-APP-ISM-0109 Application control (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events
  • E8-APP-ISM-1906 Application control (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events
  • E8-APP-ISM-1907 Application control (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events
  • E8-MFA-ISM-0109 Multi-factor authentication (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events
  • E8-MFA-ISM-1906 Multi-factor authentication (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events
  • E8-MFA-ISM-1907 Multi-factor authentication (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events
  • E8-UAH-ISM-0109 User application hardening (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events
  • E8-UAH-ISM-1906 User application hardening (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events
  • E8-UAH-ISM-1907 User application hardening (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events

PCI DSS 4.0 · 11 controls

  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 10.4.1.1 10.4.1.1 Automated mechanisms used for audit log review
  • 10.4.2 10.4.2 Periodic review of all other system component logs
  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 10.7.1 10.7.1 Service providers detect critical control failures (superseded)
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic
  • 11.5.2 11.5.2 Change detection on critical files
  • 11.6.1 11.6.1 Payment page tamper detection
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • 9.2.3 9.2.3 Physical protection of network hardware and lines

CIS Controls v8 · 8 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-13.2 Deploy a Host-Based Intrusion Detection Solution
  • CIS-13.3 Deploy a Network Intrusion Detection Solution
  • CIS-13.6 Collect Network Traffic Flow Logs
  • CIS-2.3 Address Unauthorized Software
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.2 Collect Audit Logs
  • ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts
  • ASBv3-LT-1 Enable threat detection capabilities
  • ASBv3-LT-2 Enable threat detection for identity and access management
  • ASBv3-NS-4 Deploy intrusion detection/intrusion prevention systems (IDS/IPS)
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • DP-2 Monitor anomalies and threats targeting sensitive data
  • LT-5 Centralize security log management and analysis

SOC 2 · 6 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-PI1.4 PI1.4 Controls over output delivery
  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-29 Host-based IDS/IPS (Very Good)
  • ASD37-30 Endpoint detection and response (Very Good)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-32 Network-based IDS/IPS (Limited)
  • ISM-1028 NIDS or NIPS at external gateways
  • ISM-1034 HIPS or EDR on critical servers
  • ISM-1228 Analysing cyber security events for incidents
  • ISM-1607 Monitoring and logging isolation mechanisms
  • ISM-1906 Analysing internet-facing server event logs

C5 (Germany) · 5 controls

  • C5-COS-01 Technical safeguards
  • C5-COS-03 Monitoring of connections in the Cloud Service Provider's network
  • C5-OPS-13 Logging and Monitoring - Identification of Events
  • C5-OPS-16 Logging and Monitoring - Configuration
  • C5-OPS-17 Logging and Monitoring - Availability of the Monitoring Software

CMMC 2.0 · 5 controls

  • NIST-CSF-DE.AE-03 Information is correlated from multiple sources
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • 18.4.7.C.01 18.4.7.C.01 Intrusion detection strategy for classified systems
  • 18.4.7.C.02 18.4.7.C.02 Intrusion detection strategy
  • 21.4.11.C.14 21.4.11.C.14 Continuous monitoring of BYOD for compromise
  • 7.1.7.C.01 7.1.7.C.01 Incident detection tools and procedures for classified systems
  • 7.1.7.C.02 7.1.7.C.02 Incident detection tools and procedures including network defence

HIPAA Security Rule · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

ISO 19011:2018 · 3 controls

  • 5.6 Monitoring audit programme
  • 6.3 Preparing audit activities
  • 6.4 Conducting audit activities

ISO 27701:2019 · 3 controls

  • 5.7 Performance evaluation
  • 6.9.4 Logging and monitoring
  • 7.3.10 Automated decision making
  • SEC04-BP03 Correlate and enrich security alerts
  • SEC04-BP04 Initiate remediation for non-compliant resources

DORA · 2 controls

IEC 62443 · 2 controls

  • 62443-3-3-FR3-SR-3-3 Security Functionality Verification
  • 62443-3-3-FR6-SR-6-2 Continuous Monitoring

ISO 22301:2019 · 2 controls

  • 6.1.2 Addressing risks and opportunities
  • 9.1 Monitoring, measurement, analysis and evaluation

ISO 27001:2022 · 2 controls

  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities

ISO/IEC 42001:2023 · 2 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • A.6.2.6 AI system operation and monitoring

MTCS (Singapore) · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.11.2e Threat Hunting
  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components

APRA CPS 234 · 1 control

  • SEC.MONITOR Security monitoring at network, application and transaction layers
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

ETSI EN 303 645 · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-8.16 Monitoring Activities

NIS2 Directive · 1 control

NY DFS 23 NYCRR 500 · 1 control

  • P1-2.2.1 P1-2.2.1 Detection or blocking of known and unknown network attacks

PTES · 1 control

  • PTES-3.5 Benchmark detection and response only as agreed, and record what was detected
  • SSAE18-SOC1-04 Monitoring Activities
  • TSA-SD-07 Continuous monitoring and detection
  • TSA-PSG-17 Insider threat programme
  • MTSA-Monitoring Continuous Monitoring and Logging

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.16 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 202 it maps to, and the evidence behind each claim, over MCP and REST.