EvidenceSheet

CC7.2 Monitors system components for anomalies indicating malicious acts

Monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are ana.

5
artefacts
2
held by a system
3
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • The monitoring design for system components and their operation, showing what constitutes anomalous behaviour · SIEM / log platform
  • Evidence of the coverage of the monitoring against the components in the system description · SIEM / log platform

periodic reviewEvidence produced at each review

  • Detection rules or analytics deployed, and evidence of the tuning applied over time · Document repository
  • Evidence of the sources monitored, covering infrastructure, applications, identity and, where applicable, physical and environmental conditions · Physical access / facilities
  • Records of anomalies detected during the period and of the analysis performed to determine whether they represent a security event · SIEM / log platform

governing documentDocuments that govern the control

none for this control

First move

Start with the 2 of 5 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

CC7.1 Detection and monitoring procedures for security events are in place · CC7.3 Evaluates security events to determine incident status