Frameworks / NIST SP 800-66 Rev 2 / 164.308(a)(5)(ii)(C) What else in your programme already covers this This control maps to 50 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-13.1 Centralize Security Event Alerting CIS-13.11 Tune Security Event Alerting Thresholds CIS-8.1 Establish and Maintain an Audit Log Management Process CIS-8.11 Conduct Audit Log Reviews CIS-8.2 Collect Audit Logs CIS-8.5 Collect Detailed Audit Logs NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts 10.6.3 10.6.3 Time sync configuration and time data protected 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins C5-OPS-13 Logging and Monitoring - Identification of Events AC-2(12) Account Monitoring for Atypical Usage AC-7 Unsuccessful Logon Attempts AC-2(12) Account Monitoring for Atypical Usage AC-7 Unsuccessful Logon Attempts SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3 ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components ASBv3-LT-2 Enable threat detection for identity and access management 8.16 Monitoring activities 6.9.4 Logging and monitoring 3.14.2e Monitor Organizational Systems with Specialized Capabilities CE-SC.5 Password-Based Authentication Quality Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative Query this from an agent The graph holds this control, the 50 it maps to, and the evidence behind each claim, over MCP and REST.