NIST SP 800-66 Rev 2
Administrative

NIST SP 800-66 Rev 2 164.308(a)(5)(ii)(C): Log-in Monitoring (Addressable)

Implement procedures for monitoring log-in attempts and reporting discrepancies. NIST recommends automated alerts on failed authentication thresholds and anomalous login patterns.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 50 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 6 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.2 Collect Audit Logs
  • CIS-8.5 Collect Detailed Audit Logs

NIST SP 800-53 Rev 5 · 6 controls

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

NIST SP 800-171 Rev 3 · 3 controls

PCI DSS 4.0 · 3 controls

  • 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes

C5 (Germany) · 2 controls

  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • C5-OPS-13 Logging and Monitoring - Identification of Events

CMMC 2.0 · 2 controls

FedRAMP High · 2 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-7 Unsuccessful Logon Attempts

FedRAMP Moderate · 2 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • AC-7 Unsuccessful Logon Attempts

ISO 27001:2022 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components
  • ASBv3-LT-2 Enable threat detection for identity and access management

ISO 27002:2022 · 1 control

  • 8.16 Monitoring activities

ISO 27701:2019 · 1 control

  • 6.9.4 Logging and monitoring

NIST SP 800-172 · 1 control

  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities

UK Cyber Essentials · 1 control

  • CE-SC.5 Password-Based Authentication Quality

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

Query this from an agent

The graph holds this control, the 50 it maps to, and the evidence behind each claim, over MCP and REST.