UK NCSC Cyber Assessment Framework
Objective C: Detecting cyber security events – UK NCSC Cyber Assessment Framework

UK NCSC Cyber Assessment Framework C1.a: C1.a Sources and tools for logging and monitoring

Logging and monitoring data sources and tools allow timely identification of events affecting security or resilience. Partially achieved: security data from some areas, some user and system monitoring, boundary traffic monitoring including IP connections, some searchable logs, tools working with most log data, and logs available when needed. Achieved: monitoring based on thorough understanding of systems and attacker techniques, enough detail for prompt detection and investigation, extensive user and system monitoring detecting policy violations and anomalies, host and network monitoring, new systems considered as sources, logs synchronised to a common time source, logs enriched with other data, tools that pinpoint activity, and regular review of sources and tools.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Objective C: Detecting cyber security events – UK NCSC Cyber Assessment Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.