Agencies should log the events in the table in this control for particular software components. Database: user access to the database; denied access attempts; changes to user roles or database rights; new users being added, particularly privileged users; changes to the data; and changes to the database format or structure. Network or operating system: logon and logoff attempts, whether successful or failed; changes to administrator and user accounts; unsuccessful attempts to reach data or system resources; any attempt to use special privileges; actual use of special privileges; management of users or groups; security policy changes; service failures and restarts; system startup and shutdown; configuration data changes; access to sensitive data and processes; and data import and export. Web application: user access to the web application; denied access attempts; user access to web documents; and search engine queries that users make.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.