A.8.16Monitoring activities
Monitor networks, systems and applications for unusual behavior that could indicate a security incident, and act on what you find.
A.8.16 is covered by 60 Sekit CSF controls. +55 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
NIST CSF 2.0 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
In practice
Monitoring only earns its name when someone looks at the alerts. What works for an SME: centralize logs into a SIEM or lightweight equivalent, define a short list of detection use cases that matter for the business rather than importing every vendor default, and commit to triaging alerts within a set timeframe so genuine signals do not drown in noise. EDR on endpoints catching and auto-containing threats does more real-world work than a large rule library nobody tunes. Auditors ask what the last three alerts were, how fast they were triaged, and whether anyone tuned out the recurring false positive that made the team stop looking.
Common gaps
Questions your auditor will ask
Where regulation demands it
Related controls
Via the shared Sekit CSF topic, not the framework's own index.