CC7.2 Monitors system components for anomalies indicating malicious acts
Monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are ana.
5
artefacts
2
held by a system
3
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- The monitoring design for system components and their operation, showing what constitutes anomalous behaviour · SIEM / log platform
- Evidence of the coverage of the monitoring against the components in the system description · SIEM / log platform
periodic reviewEvidence produced at each review
- Detection rules or analytics deployed, and evidence of the tuning applied over time · Document repository
- Evidence of the sources monitored, covering infrastructure, applications, identity and, where applicable, physical and environmental conditions · Physical access / facilities
- Records of anomalies detected during the period and of the analysis performed to determine whether they represent a security event · SIEM / log platform
governing documentDocuments that govern the control
none for this control
First move
Start with the 2 of 5 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Logs collected without any detection logic applied, so anomalies are only visible in hindsight
- Monitoring covers malicious acts and omits natural disaster and error, both of which the criterion names
- Alert volume exceeding triage capacity, so alerts are closed without analysis
- Components in the system description with no monitoring coverage at all
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetCC7.1 Detection and monitoring procedures for security events are in place · CC7.3 Evaluates security events to determine incident status