Logging and monitoring data sources and tools allow timely identification of events affecting security or resilience. Partially achieved: security data from some areas, some user and system monitoring, boundary traffic monitoring including IP connections, some searchable logs, tools working with most log data, and logs available when needed. Achieved: monitoring based on thorough understanding of systems and attacker techniques, enough detail for prompt detection and investigation, extensive user and system monitoring detecting policy violations and anomalies, host and network monitoring, new systems considered as sources, logs synchronised to a common time source, logs enriched with other data, tools that pinpoint activity, and regular review of sources and tools.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.