Frameworks / NIST SP 800-66 Rev 2 / 164.308(a)(1)(ii)(D) NIST SP 800-66 Rev 2
Administrative
NIST SP 800-66 Rev 2 164.308(a)(1)(ii)(D): Information System Activity Review (Required) Regularly review audit logs, access reports, and security incident tracking reports. NIST recommends defined review frequency, SIEM integration, anomaly detection, and documented review evidence.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 113 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.2 1.2.2 Network connection and NSC changes under change control 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data 10.2.1.3 10.2.1.3 Access to the audit logs is itself logged 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials 10.4.1 10.4.1 Daily review of security-relevant logs 10.4.2 10.4.2 Periodic review of all other system component logs 10.4.3 10.4.3 Exceptions and anomalies from log review addressed 10.6.3 10.6.3 Time sync configuration and time data protected 10.7.2 10.7.2 Detect and alert on critical security control failures 10.7.3 10.7.3 Respond promptly to critical security control failures 11.5.2 11.5.2 Change detection on critical files 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program 5.3.4 5.3.4 Anti-malware audit logs enabled and retained 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically 9.2.3 9.2.3 Physical protection of network hardware and lines 7.2.4 7.2.4 User accounts and privileges reviewed every six months CIS-1.4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory CIS-13.1 Centralize Security Event Alerting CIS-2.3 Address Unauthorized Software CIS-8.1 Establish and Maintain an Audit Log Management Process CIS-8.11 Conduct Audit Log Reviews CIS-8.12 Collect Service Provider Logs CIS-8.2 Collect Audit Logs CIS-8.9 Centralize Audit Logs ASBv3-BR-3 Monitor backups ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts ASBv3-LT-1 Enable threat detection capabilities ASBv3-PA-4 Review and reconcile user access regularly DP-2 Monitor anomalies and threats targeting sensitive data LT-5 Centralize security log management and analysis AC-2(12) Account Monitoring for Atypical Usage AU-6 Audit Record Review, Analysis, and Reporting AU-6(1) Automated Process Integration AU-6(3) Correlate Audit Record Repositories SA-1 Policy and Procedures SI-4 System Monitoring AC-2(12) Account Monitoring for Atypical Usage AU-6 Audit Record Review, Analysis, and Reporting AU-6(1) Automated Process Integration AU-6(3) Correlate Audit Record Repositories SA-1 Policy and Procedures SI-4 System Monitoring NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities NIST-CSF-DE.AE-03 Information is correlated from multiple sources NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved 03.03.05 Audit Record Review, Analysis, and Reporting 03.03.06 Audit Record Reduction and Report Generation 03.06.02 Incident Monitoring, Reporting, and Response Assistance 03.12.03 Continuous Monitoring 03.14.06 System Monitoring SEC02-BP05 Audit and rotate credentials periodically SEC03-BP07 Analyze public and cross-account access SEC04-BP02 Capture logs, findings, and metrics in standardized locations SEC04-BP03 Correlate and enrich security alerts C5-COM-04 Information on information security performance and management assessment of the ISMS C5-IDM-05 Regular review of access rights C5-OPS-10 Logging and Monitoring - Concept C5-OPS-13 Logging and Monitoring - Identification of Events 5.25 Assessment and decision on information security events 5.35 Independent review of information security 8.15 Logging 8.16 Monitoring activities 5.25 Assessment and decision on information security events 5.35 Independent review of information security 8.15 Logging 8.16 Monitoring activities SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program AUCDR-IS-STEP5 Step 5 - Manage and report security incidents E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) E8-APP-ML3 Application Control (ML3) CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-P30 Monitoring, Review and Testing of Control Effectiveness CPS234-22 Systematic Control Testing Program CPS234-30 Detection and Response Mechanisms ASD37-28 Continuous incident detection and response (Excellent) ASD37-31 Hunt to discover incidents (Very Good) 9.1 Monitoring, measurement, analysis and evaluation 9.2.2 Audit programme(s) 6.9.4 Logging and monitoring 6.9.7 Information systems audit considerations 3.11.3e Advanced Automation and Analytics Capabilities 3.14.2e Monitor Organizational Systems with Specialized Capabilities ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components CBPR-PR-32 Detection, prevention and response measures Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative Query this from an agent The graph holds this control, the 113 it maps to, and the evidence behind each claim, over MCP and REST.