Evidence of potential incidents in monitoring data is reliably identified and triggers alerts where appropriate. Partially achieved: known indicators of compromise are detected, updates and new signatures applied in a timely way, alerts prioritised, enrichment performed separately, a shared process for staff to report events, some automated actions, irregular anomaly monitoring and regular log review. Achieved: detection of indicators and behavioural abnormalities, prompt application of all updates, prioritised alerts supporting incident management, near real time enrichment within the alert, regularly tested and tuned detections distinguishing genuine incidents, custom as well as off-the-shelf rules, and continuous near real time monitoring.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.