SI.L2-3.14.7 Identify Unauthorized Use
Define what constitutes authorized use of organizational systems, and identify use that falls outside that definition.
3
artefacts
1
held by a system
1
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Monitoring or detection capability identifying use outside that definition · SIEM / log platform
periodic reviewEvidence produced at each review
- Records of identified unauthorized use and the response · Document repository
governing documentDocuments that govern the control
- Documented definition of authorized system use · Document repository
First move
Start with the 1 of 3 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Authorized use never defined so unauthorized use cannot be identified
- Detection focused on external attack while insider misuse is unaddressed
- Identified misuse not recorded or acted on
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet