OWASP DevSecOps Maturity Model (DSOMM) DSOMM-5: Information Gathering, Logging, Monitoring, and Incident Response
Per OWASP DSOMM Information Gathering dimension and operational monitoring: implement observability + detection + response. Requirements include (a) collect security telemetry from application + infrastructure + identity + access layers + (b) implement runtime threat detection + application-layer protections + (c) operate alerting + anomaly detection with triage + investigation workflows + (d) maintain production-to-development feedback loops including security findings + remediation + (e) operate incident response readiness including playbooks + tabletops + on-call + (f) integrate with SIEM + SOC + threat intelligence + (g) align logging retention + handling with regulatory + investigative + governance requirements.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 44 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ITU-Scope-Constitution-Convention-Radio-Regulations-WRC-Quadrennial-Treaty-Art1-Definitions ITU Constitution + Convention + Radio Regulations Scope + Article 1 Definitions + Article 2 Nomenclature + WRC World Radiocommunication Conference Quadrennial Treaty Process + Member States + Sector Members
ITU-Space-Services-Art21-Art22-Art23-PFD-EPFD-Limits-NGSO-Constellation-Milestones-Bringing-Into-Use ITU Radio Regulations Article 21 Terrestrial and Space Sharing + Article 22 Space Services + Article 23 Time Signal + PFD Power Flux Density + EPFD Equivalent PFD + NGSO Non-Geostationary Constellation Milestones + Bringing Into Use