Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.PS-04 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-04: Log records are generated and made available for continuous monitoring Log records are generated and made available for continuous monitoring. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 214 controls across 62 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-17(1) Monitoring and Control AC-2(4) Automated Audit Actions AC-6(9) Log Use of Privileged Functions AU-12 Audit Record Generation AU-2 Event Logging AU-3 Content of Audit Records AU-3(1) Additional Audit Information AU-4 Audit Log Storage Capacity AU-5 Response to Audit Logging Process Failures AU-6(1) Automated Process Integration AU-7 Audit Record Reduction and Report Generation AU-8 Time Stamps CA-7 Continuous Monitoring CA-8 Penetration Testing CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1)) IR-4 Incident Handling IR-5 Incident Monitoring IR-6(1) Automated Reporting MP-5 Media Transport SA-1 Policy and Procedures SI-12 Information Management and Retention SI-4 System Monitoring SR-10 Inspection of Systems or Components (SR-10) AC-17(1) Monitoring and Control AC-2(4) Automated Audit Actions AC-6(9) Log Use of Privileged Functions AU-12 Audit Record Generation AU-2 Event Logging AU-3 Content of Audit Records AU-3(1) Additional Audit Information AU-4 Audit Log Storage Capacity AU-5 Response to Audit Logging Process Failures AU-6(1) Automated Process Integration AU-7 Audit Record Reduction and Report Generation AU-8 Time Stamps CA-7 Continuous Monitoring CA-8 Penetration Testing CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records (CM-5(1)) IR-4 Incident Handling IR-5 Incident Monitoring IR-6(1) Automated Reporting MP-5 Media Transport SA-1 Policy and Procedures SI-12 Information Management and Retention SI-4 System Monitoring SR-10 Inspection of Systems or Components (SR-10) 10.2.1 10.2.1 Audit logging enabled on all system components 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data 10.2.1.2 10.2.1.2 Logs capture all administrative actions 10.2.1.3 10.2.1.3 Access to the audit logs is itself logged 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials 10.2.1.6 10.2.1.6 Logs capture initialization and stopping of audit logs 10.2.1.7 10.2.1.7 Logs capture creation and deletion of system-level objects 10.2.2 10.2.2 Required details recorded for each auditable event 10.4.2 10.4.2 Periodic review of all other system component logs 10.5.1 10.5.1 Keep logs 12 months, latest three months online 10.6.3 10.6.3 Time sync configuration and time data protected 10.7.2 10.7.2 Detect and alert on critical security control failures 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program 5.3.4 5.3.4 Anti-malware audit logs enabled and retained CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-13.1 Centralize Security Event Alerting CIS-3.14 Log Sensitive Data Access CIS-8.1 Establish and Maintain an Audit Log Management Process CIS-8.10 Retain Audit Logs CIS-8.11 Conduct Audit Log Reviews CIS-8.2 Collect Audit Logs CIS-8.3 Ensure Adequate Audit Log Storage CIS-8.5 Collect Detailed Audit Logs CIS-8.6 Collect DNS Query Audit Logs CIS-8.7 Collect URL Request Audit Logs CIS-8.8 Collect Command-Line Audit Logs CIS-8.9 Centralize Audit Logs C5-DEV-07 Logging of changes C5-OPS-10 Logging and Monitoring - Concept C5-OPS-11 Logging and Monitoring - Metadata Management Concept C5-OPS-12 Logging and Monitoring - Access, Storage and Deletion C5-OPS-14 Logging and Monitoring - Storage of the Logging Data C5-OPS-15 Logging and Monitoring - Accountability C5-PSS-04 Error handling and Logging Mechanisms 5.5.5 Documented information 5.6 Operation 6.9 Operations security 6.9.4 Logging and monitoring 6.9.7 Information systems audit considerations 7.2.8 Records related to processing PII 7.5.3 Records of transfer of PII ASBv3-DS-7 Enable logging and monitoring in DevOps ASBv3-LT-6 Configure log storage retention ASBv3-LT-7 Use approved time synchronization sources LT-3 Enable logging for security investigation LT-5 Centralize security log management and analysis ISM-0585 Details captured for each logged event ISM-1405 Implementing a centralised event logging facility ISM-1983 Timely forwarding to the centralised facility ISM-1988 Searchable retention for 12 months 7.5 Documented information 7.5.3 Control of documented information A.6.2.6 AI system operation and monitoring A.6.2.8 AI system recording of event logs E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) E8-APP-ML2 Application Control (ML2) E8-UAH-ML3 User Application Hardening - Maturity Level 3 ASD37-29 Host-based IDS/IPS (Very Good) ASD37-32 Network-based IDS/IPS (Limited) ASD37-33 Capture network traffic (Limited) 5.28 Collection of evidence 5.33 Protection of records 8.15 Logging SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies SOC2-PI1.5 PI1.5 Controls over stored inputs, work in process and outputs ANSSI-HYG-22 Put in Place a Secure Internet Access Gateway ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components APPI-A29 Records When Providing Personal Data to a Third Party APPI-A30 Confirmation and Records When Receiving Personal Data from a Third Party SEC04-BP01 Configure service and application logging SEC04-BP02 Capture logs, findings, and metrics in standardized locations API1164-13 Business Continuity and Recovery AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV) BSI-17 Continuous monitoring strategy ITSG33-AU Audit and Accountability (AU) CAT-D3-2 Detective controls FDBR-Enforcement-AG-CurePeriod Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722) ICP-24 Macroprudential Surveillance and Insurance Supervision IEC62443-13 Network security monitoring 7.5 Documented information ISO28001-PS-01 Facility Security 27006-9.4 Surveillance and recertification ISO27019-13 Network security monitoring 27400-6.5 Security monitoring and incident response Art.23.4.b Submit an incident notification within 72 hours, with an initial assessment and indicators of compromise PR.PT-1 PR.PT-1: Audit/log records are determined, documented, implemented, and reviewed in accordance with policy PR.PT-1 PR.PT-1: Audit/log records are determined, documented, implemented, and reviewed in accordance with policy NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition 3.11.3e Advanced Automation and Analytics Capabilities PR.PS-04 PR.PS-04 Log records generated and kept for detection, response and recovery NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC NZISM-5 Network Security, System Hardening, and Application Security OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification IM8-SEC.3 Network Security ISMSP-SYS-03 Security Monitoring and Log Management TSAPIPE-2 OT/IT Network Segmentation and Access Control UK-TSA-MON-01 Security Monitoring US-SEC-DA-SC-03 ETF Framework Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-04 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 214 it maps to, and the evidence behind each claim, over MCP and REST.